logo

Under Attack: Critical Fortinet Auth Bypass (CVE-2026-24858) Exploited in the Wild

ID: 06667ad9-7493-5c0e-8eee-5b2b66f0d8b5

STIX ID: report--06667ad9-7493-5c0e-8eee-5b2b66f0d8b5

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-28

Date Updated: 2026-04-23

Author: Ddos

...
...

Fortinet disclosed CVE-2026-24858, a critical (CVSS 9.4) FortiCloud SSO authentication-bypass affecting FortiOS, FortiManager, and FortiAnalyzer that has been exploited in the wild by two malicious FortiCloud accounts ([email protected] and [email protected]); attackers used those accounts to log into other registered devices and create persistent local administrative accounts. Fortinet identified and locked the accounts, temporarily disabled FortiCloud SSO server-side (re-enabling it only for patched devices), published IoCs including several Cloudflare IPs and two additional IPs, and urged customers to apply device patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.