logo

Fortinet blocks exploited FortiCloud SSO zero day until patch is ready

ID: 2da37b00-3177-5425-a361-ccba7b4f89a8

STIX ID: report--2da37b00-3177-5425-a361-ccba7b4f89a8

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-01-27

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Fortinet confirmed active exploitation of a critical FortiCloud SSO authentication bypass (CVE-2026-24858) that allows attackers to authenticate to other customers' FortiOS, FortiManager, and FortiAnalyzer devices, create local administrative accounts, and exfiltrate firewall configurations; Fortinet has implemented server-side mitigations (disabling abused FortiCloud accounts and globally restricting FortiCloud SSO for vulnerable devices) and recommends treating impacted devices as fully compromised until patches are released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.