logo

CISA Warns of FortiCloud SSO Authentication Bypass Vulnerability Exploited in Attacks

ID: 54ca29e4-f2bd-572e-9820-87af79f96091

STIX ID: report--54ca29e4-f2bd-572e-9820-87af79f96091

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-01-29

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive Summary:** CVE-2026-24858 is a critical (CVSS 9.1) authentication bypass in FortiCloud SSO affecting FortiAnalyzer, FortiManager, FortiOS, and FortiProxy; CISA has added it to the Known Exploited Vulnerabilities catalog after reports of active abuse. Attackers can register low‑privilege devices to capture and replay SSO tokens to gain administrative access for lateral movement and ransomware staging; Fortinet has published fixes and recommends disabling FortiCloud SSO, enforcing MFA, and monitoring for anomalous logins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.