logo

CVE-2026-24858: Patch Released for Fortinet FortiOS SSO Authentication Bypass

ID: 68dbcb7b-09b7-5de7-81bb-40dc8d753077

STIX ID: report--68dbcb7b-09b7-5de7-81bb-40dc8d753077

Feed Name: SOCRadar Blog

Threat Score
85/100

Date Published: 2026-01-28

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

This report describes CVE-2026-24858, a critical Fortinet FortiCloud SSO authentication bypass (CVSS 9.4) that has been exploited in the wild to obtain administrative access to FortiOS and related products; it includes affected products/versions, observed malicious FortiCloud accounts and IPs, typical post-compromise actions (config download, creation of local admin accounts, VPN changes), recommended remediation steps, and notes a concurrent Microsoft Office zero-day (CVE-2026-21509) also under active exploitation and listed in CISA's KEV.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.