logo

CVE-2026-24858: FortiCloud SSO Authentication Bypass Vulnerability Exploited

ID: 5e71eefc-d9e2-5ed2-96e0-ce03581f105d

STIX ID: report--5e71eefc-d9e2-5ed2-96e0-ce03581f105d

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2026-01-28

Date Updated: 2026-07-26

Author: Julian Tuin

...
...

**Executive Summary:** On January 27, 2026 Fortinet disclosed CVE-2026-24858, a critical FortiCloud SSO authentication bypass affecting FortiOS, FortiAnalyzer, FortiManager, and FortiProxy; threat actors with a FortiCloud account and a registered device could authenticate to other registered devices, create local administrative accounts for persistence, and exfiltrate configuration data. Arctic Wolf observed related active exploitation and recommends upgrading to fixed product versions, restricting management interface access, enabling comprehensive log monitoring, and restoring clean firmware/configurations if compromise is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.