CISA Warns of FortiCloud SSO Authentication Bypass Vulnerability Exploited in Attacks
ID: 54ca29e4-f2bd-572e-9820-87af79f96091
STIX ID: report--54ca29e4-f2bd-572e-9820-87af79f96091
Feed Name: cybersecurityNews.com
**Executive Summary:** CVE-2026-24858 is a critical (CVSS 9.1) authentication bypass in FortiCloud SSO affecting FortiAnalyzer, FortiManager, FortiOS, and FortiProxy; CISA has added it to the Known Exploited Vulnerabilities catalog after reports of active abuse. Attackers can register low‑privilege devices to capture and replay SSO tokens to gain administrative access for lateral movement and ransomware staging; Fortinet has published fixes and recommends disabling FortiCloud SSO, enforcing MFA, and monitoring for anomalous logins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
