Fortinet unearths another critical bug as SSO accounts borked post-patch
ID: 9503a08c-9065-599c-8171-4b528ba31c3b
STIX ID: report--9503a08c-9065-599c-8171-4b528ba31c3b
Feed Name: The Register (Security)
Threat Score
A critical authentication-bypass vulnerability (CVE-2026-24858, CVSS 9.4) in Fortinet's FortiCloud SSO was observed exploited in the wild by two malicious FortiCloud accounts, enabling cross-account administrative logins against FortiAnalyzer, FortiManager, FortiOS and FortiProxy; Fortinet has disabled FortiCloud SSO for vulnerable versions while patches are developed and continues investigations into FortiWeb and FortiSwitch Manager exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
