logo

Fortinet Confirms Critical FortiCloud SSO Vulnerability(CVE-2026-24858) Actively Exploited in the Wild

ID: 16b20ce2-6978-533b-8c47-f9d4f22b795c

STIX ID: report--16b20ce2-6978-533b-8c47-f9d4f22b795c

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-01-28

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Fortinet confirmed a critical authentication-bypass zero-day (CVE-2026-24858, CVSS 9.4) in FortiCloud SSO that is being actively exploited: attackers with FortiCloud accounts and registered devices could log into other registered devices, download configuration files for reconnaissance, and create persistent local admin accounts. Fortinet published affected versions and upgrade paths, provided CLI/GUI mitigations (including disabling FortiCloud SSO), and released IoCs (malicious SSO accounts, IP addresses, and local account names) for threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.