logo

Fortinet patches actively exploited FortiOS SSO auth bypass (CVE-2026-24858)

ID: ba4b7e93-0e4c-5f17-8279-945fb4224b3e

STIX ID: report--ba4b7e93-0e4c-5f17-8279-945fb4224b3e

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-01-28

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Fortinet released fixes for a critical FortiOS/FortiManager/FortiAnalyzer SSO authentication bypass (CVE-2026-24858, CVSS 9.4) that has been actively exploited; attackers with malicious FortiCloud accounts automated admin logins, exported configurations (including hashed credentials), created persistent admin users, and enabled VPN access. Fortinet temporarily disabled FortiCloud SSO, blocked malicious accounts, and is forcing upgrades while investigating broader SAML SSO impact; the activity resembles prior December 2025 campaigns exploiting similar SSO flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.