CVE-2026-24858: FortiCloud SSO Authentication Bypass Vulnerability Exploited
ID: 5e71eefc-d9e2-5ed2-96e0-ce03581f105d
STIX ID: report--5e71eefc-d9e2-5ed2-96e0-ce03581f105d
Feed Name: Arctic Wolf
**Executive Summary:** On January 27, 2026 Fortinet disclosed CVE-2026-24858, a critical FortiCloud SSO authentication bypass affecting FortiOS, FortiAnalyzer, FortiManager, and FortiProxy; threat actors with a FortiCloud account and a registered device could authenticate to other registered devices, create local administrative accounts for persistence, and exfiltrate configuration data. Arctic Wolf observed related active exploitation and recommends upgrading to fixed product versions, restricting management interface access, enabling comprehensive log monitoring, and restoring clean firmware/configurations if compromise is suspected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
