Fortinet Confirms New Zero-Day Behind Malicious SSO Logins
ID: ecbd19ac-872f-53e8-ab6b-5f2b425ccc96
STIX ID: report--ecbd19ac-872f-53e8-ab6b-5f2b425ccc96
Feed Name: Dark Reading
Fortinet disclosed CVE-2026-24858, a critical (CVSS 9.8) authentication-bypass zero-day affecting FortiOS, FortiManager, FortiAnalyzer, FortiProxy, and FortiWeb that allows attackers with a FortiCloud account and a registered device to log into other users' devices via FortiCloud SSO; the flaw has been actively exploited, traced to two FortiCloud accounts, added to CISA's KEV catalog, and prompted Fortinet to temporarily disable FortiCloud SSO and push updates while Shadowserver reports roughly 10,000 exposed instances with SSO enabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
