Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected

Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected

Fortinet has issued security updates after active exploitation of a critical FortiOS FortiCloud SSO authentication bypass (CVE-2026-24858) that also impacts FortiManager and FortiAnalyzer. The company disabled and re-enabled FortiCloud SSO to block malicious accounts and now requires customers to upgrade firmware, audit configurations, and rotate credentials. #CVE-2026-24858 #FortiCloud

Keypoints

  • CVE-2026-24858 (CVSS 9.4) is an authentication-bypass in FortiCloud SSO affecting FortiOS, FortiManager, and FortiAnalyzer.
  • An attacker with a FortiCloud account and a registered device can log into other devices if FortiCloud SSO is enabled.
  • Threat actors used the flaw to create local admin accounts, alter VPN settings for persistence, and exfiltrate firewall configurations.
  • Fortinet locked malicious FortiCloud accounts, temporarily disabled SSO, and now restricts FortiCloud SSO logins until devices are updated.
  • CISA added CVE-2026-24858 to its KEV catalog, mandating federal remediation by January 30, 2026; customers should update firmware, restore or audit configs, and rotate credentials.

Read More: https://thehackernews.com/2026/01/fortinet-patches-cve-2026-24858-after.html