Warning: Actively exploited 0-day critical vulnerability in FortiOS, FortiManager and FortiAnalyzer, Patch Immediately!
ID: a3133c79-d712-588c-8fc4-9c626270aa50
STIX ID: report--a3133c79-d712-588c-8fc4-9c626270aa50
Feed Name: CCB Advisories Feed
Threat Score
Fortinet and the Centre for Cybersecurity Belgium warn of CVE-2026-24858, a critical (CVSS 9.4) 0-day authentication bypass affecting FortiOS, FortiManager and FortiAnalyzer when FortiCloud SSO is enabled; the flaw has been actively exploited to create administrative accounts and download customer configuration files, and organisations are urged to urgently apply vendor updates, restrict administrative access, disable unused FortiCloud SSO, and monitor IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
