logo

Fortinet Confirms New Zero-Day Behind Malicious SSO Logins

ID: ecbd19ac-872f-53e8-ab6b-5f2b425ccc96

STIX ID: report--ecbd19ac-872f-53e8-ab6b-5f2b425ccc96

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-01-28

Date Updated: 2026-05-05

Author: Rob Wright

...
...

Fortinet disclosed CVE-2026-24858, a critical (CVSS 9.8) authentication-bypass zero-day affecting FortiOS, FortiManager, FortiAnalyzer, FortiProxy, and FortiWeb that allows attackers with a FortiCloud account and a registered device to log into other users' devices via FortiCloud SSO; the flaw has been actively exploited, traced to two FortiCloud accounts, added to CISA's KEV catalog, and prompted Fortinet to temporarily disable FortiCloud SSO and push updates while Shadowserver reports roughly 10,000 exposed instances with SSO enabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.