logo

Warning: Actively exploited 0-day critical vulnerability in FortiOS, FortiManager and FortiAnalyzer, Patch Immediately!

ID: a3133c79-d712-588c-8fc4-9c626270aa50

STIX ID: report--a3133c79-d712-588c-8fc4-9c626270aa50

Feed Name: CCB Advisories Feed

Threat Score
90/100

Date Published: 2026-01-28

Date Updated: 2026-07-24

...
...

Fortinet and the Centre for Cybersecurity Belgium warn of CVE-2026-24858, a critical (CVSS 9.4) 0-day authentication bypass affecting FortiOS, FortiManager and FortiAnalyzer when FortiCloud SSO is enabled; the flaw has been actively exploited to create administrative accounts and download customer configuration files, and organisations are urged to urgently apply vendor updates, restrict administrative access, disable unused FortiCloud SSO, and monitor IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.