Fortinet’s latest zero-day vulnerability carries frustrating familiarities for customers
ID: cdf41675-f873-5fba-816e-a823b7897cd9
STIX ID: report--cdf41675-f873-5fba-816e-a823b7897cd9
Feed Name: CyberScoop
Threat Score
**Executive Summary:** Fortinet is facing active exploitation of a critical authentication-bypass zero-day (CVE-2026-24858, CVSS 9.8) that permits attackers with FortiCloud accounts to log into and reconfigure Fortinet devices across multiple product lines; the flaw has been observed in the wild, prompted CISA advisories, affected thousands of devices with SSO enabled, and has led Fortinet to temporarily disable FortiCloud SSO while controls and mitigations are deployed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
