logo

CVE-2026-24858: FortiOS SSO Zero-Day Exploited in the Wild

ID: 160e7fe8-694a-5739-b299-14b8215390af

STIX ID: report--160e7fe8-694a-5739-b299-14b8215390af

Feed Name: SOC Prime Blog

Threat Score
88/100

Date Published: 2026-01-28

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

Fortinet disclosed CVE‑2026‑24858, a critical FortiCloud SSO authentication‑bypass (CVSS 9.4) that allows attackers with a FortiCloud account and a registered device to access devices tied to other accounts; the flaw was actively exploited in the wild, prompting Fortinet to suspend FortiCloud SSO temporarily and CISA to add the CVE to its Known Exploited Vulnerabilities catalog. Fortinet and industry guidance strongly advise immediate patching, disabling FortiCloud SSO where appropriate, and other mitigations to prevent unauthorized administrative access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.