Under Attack: Critical Fortinet Auth Bypass (CVE-2026-24858) Exploited in the Wild
ID: 06667ad9-7493-5c0e-8eee-5b2b66f0d8b5
STIX ID: report--06667ad9-7493-5c0e-8eee-5b2b66f0d8b5
Feed Name: securityonline.info
Fortinet disclosed CVE-2026-24858, a critical (CVSS 9.4) FortiCloud SSO authentication-bypass affecting FortiOS, FortiManager, and FortiAnalyzer that has been exploited in the wild by two malicious FortiCloud accounts ([email protected] and [email protected]); attackers used those accounts to log into other registered devices and create persistent local administrative accounts. Fortinet identified and locked the accounts, temporarily disabled FortiCloud SSO server-side (re-enabling it only for patched devices), published IoCs including several Cloudflare IPs and two additional IPs, and urged customers to apply device patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
