Fortinet Confirms Critical FortiCloud SSO Vulnerability(CVE-2026-24858) Actively Exploited in the Wild
ID: 16b20ce2-6978-533b-8c47-f9d4f22b795c
STIX ID: report--16b20ce2-6978-533b-8c47-f9d4f22b795c
Feed Name: cybersecurityNews.com
Fortinet confirmed a critical authentication-bypass zero-day (CVE-2026-24858, CVSS 9.4) in FortiCloud SSO that is being actively exploited: attackers with FortiCloud accounts and registered devices could log into other registered devices, download configuration files for reconnaissance, and create persistent local admin accounts. Fortinet published affected versions and upgrade paths, provided CLI/GUI mitigations (including disabling FortiCloud SSO), and released IoCs (malicious SSO accounts, IP addresses, and local account names) for threat hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
