logo

CVE-2026-24858: FortiCloud SSO Authentication Bypass Vulnerability Exploited

ID: cc3ac2c4-1248-54ac-a367-cf16b87ed69e

STIX ID: report--cc3ac2c4-1248-54ac-a367-cf16b87ed69e

Feed Name: Arctic Wolf

Threat Score
85/100

Date Published: 2026-01-28

Date Updated: 2026-07-26

Author: Julian Tuin

...
...

**Executive summary:** Fortinet disclosed CVE-2026-24858, a critical FortiCloud SSO authentication bypass affecting multiple FortiOS, FortiAnalyzer, FortiManager, and FortiProxy releases; Arctic Wolf observed active exploitation where attackers used FortiCloud SSO to log into other registered devices, create persistent local administrative accounts, and exfiltrate configurations. The advisory lists affected and fixed versions, recommends upgrading to patched releases, limiting management interface exposure, enabling log monitoring, and restoring clean firmware/configurations if compromise is suspected; disabling FortiCloud SSO is noted as a prior workaround though Fortinet states current mitigations limit its necessity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.