Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
ID: 2da37b00-3177-5425-a361-ccba7b4f89a8
STIX ID: report--2da37b00-3177-5425-a361-ccba7b4f89a8
Feed Name: Bleeping Computer
Fortinet confirmed active exploitation of a critical FortiCloud SSO authentication bypass (CVE-2026-24858) that allows attackers to authenticate to other customers' FortiOS, FortiManager, and FortiAnalyzer devices, create local administrative accounts, and exfiltrate firewall configurations; Fortinet has implemented server-side mitigations (disabling abused FortiCloud accounts and globally restricting FortiCloud SSO for vulnerable devices) and recommends treating impacted devices as fully compromised until patches are released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
