CVE-2026-24858: Patch Released for Fortinet FortiOS SSO Authentication Bypass
ID: 68dbcb7b-09b7-5de7-81bb-40dc8d753077
STIX ID: report--68dbcb7b-09b7-5de7-81bb-40dc8d753077
Feed Name: SOCRadar Blog
This report describes CVE-2026-24858, a critical Fortinet FortiCloud SSO authentication bypass (CVSS 9.4) that has been exploited in the wild to obtain administrative access to FortiOS and related products; it includes affected products/versions, observed malicious FortiCloud accounts and IPs, typical post-compromise actions (config download, creation of local admin accounts, VPN changes), recommended remediation steps, and notes a concurrent Microsoft Office zero-day (CVE-2026-21509) also under active exploitation and listed in CISA's KEV.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
