Fortinet Confirms Critical FortiCloud SSO Vulnerability(CVE-2026-24858) Actively Exploited in the Wild
Fortinet has identified a critical authentication bypass vulnerability in its FortiCloud Single Sign-On (SSO) feature, designated as CVE-2026-24858. This vulnerability is actively exploited and affects several products, including FortiOS, FortiManager,…
Fortinet has identified a critical authentication bypass vulnerability in its FortiCloud Single Sign-On (SSO) feature, designated as CVE-2026-24858. This vulnerability is actively exploited and affects several products, including FortiOS, FortiManager, FortiAnalyzer, and FortiProxy.
The vulnerability, with a CVSSv3 score of 9.4, arises from improper access control within the GUI component. It allows attackers with a FortiCloud account and a registered device to log into other devices registered to different accounts if FortiCloud SSO is activated. This feature is not enabled by default but is activated during FortiCare registration unless explicitly disabled by administrators.
Fortinet detected malicious activities from two FortiCloud accounts and disabled them on January 22, 2026. To protect users, Fortinet temporarily disabled FortiCloud SSO on January 26, re-enabling it the next day with restrictions on vulnerable versions. Post-authentication, attackers were able to download configuration files and create local admin accounts. Fortinet advises reviewing all admin accounts for anomalies.
Affected Products and Recommended Actions
Fortinet recommends urgent upgrades to mitigate this vulnerability. The following table outlines affected versions and solutions:
Product Affected Versions Solution
FortiAnalyzer 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above
FortiAnalyzer 7.4 7.4.0 through 7.4.9 Upgrade to 7.4.10 or above
FortiAnalyzer 7.2 7.2.0 through 7.2.11 Upgrade to 7.2.12 or above
FortiAnalyzer 7.0 7.0.0 through 7.0.15 Upgrade to 7.0.16 or above
FortiAnalyzer 6.4 Not affected N/A
FortiManager 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above
FortiManager 7.4 7.4.0 through 7.4.9 Upgrade to 7.4.10 or above
FortiManager 7.2 7.2.0 through 7.2.11 Upgrade to 7.2.13 or above
Fortinet has identified a critical authentication bypass vulnerability in its FortiCloud Single Sign-On (SSO) feature, designated as CVE-2026-24858.
FortiManager 7.0 7.0.0 through 7.0.15 Upgrade to 7.0.16 or above
FortiManager 6.4 Not affected N/A
FortiOS 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above
FortiOS 7.4 7.4.0 through 7.4.10 Upgrade to 7.4.11 or above
FortiOS 7.2 7.2.0 through 7.2.12 Upgrade to 7.2.13 or above
FortiOS 7.0 7.0.0 through 7.0.18 Upgrade to 7.0.19 or above
FortiOS 6.4 Not affected N/A
FortiProxy 7.6 7.6.0 through 7.6.4 Upgrade to 7.6.6 or above
FortiProxy 7.4 7.4.0 through 7.4.12 Upgrade to 7.4.13 or above
FortiProxy 7.2 All versions Migrate to fixed release
FortiProxy 7.0 All versions Migrate to fixed release
Fortinet has provided indicators of compromise (IoCs) for monitoring potential threats:
Type IoC Value
SSO Login Accounts cloud-noc@mail[.]io
cloud-init@mail[.]io
IP Addresses 104.28.244[.]115
217.119.139[.]50
Malicious Local Accounts audit
Fortinet has implemented measures to block vulnerable devices from using FortiCloud SSO. For additional protection, administrators can disable this feature locally:
FortiOS/FortiProxy CLI : config system global set admin-forticloud-sso-login disable end FortiManager/FortiAnalyzer CLI : config system saml set forticloud-sso disable end
For GUI navigation, use: System > Settings (toggle off) or System Settings > SAML SSO.
For further details, visit the Fortinet advisory .
Based on reporting by Cyber Security News.
