Fortinet Disables FortiCloud SSO Following 0-day Vulnerability Exploited in the Wild
Fortinet has temporarily disabled its FortiCloud Single Sign-On (SSO) service following the identification of an exploited zero-day authentication bypass vulnerability across multiple products.
Fortinet has temporarily disabled its FortiCloud Single Sign-On (SSO) service following the identification of an exploited zero-day authentication bypass vulnerability across multiple products.
This vulnerability, referred to as FG-IR-26-060, enables attackers with a malicious FortiCloud account to access devices registered under different accounts. It involves an authentication bypass using an alternate path or channel vulnerability (CWE-288) and impacts FortiOS, FortiManager, and FortiAnalyzer when FortiCloud SSO is activated. This feature is not enabled by default.
Attackers can leverage this vulnerability to gain administrative access to targeted devices, including those with previous patches. While all SAML SSO implementations are affected, exploitation has been primarily observed in FortiCloud SSO. Investigations continue for FortiWeb and FortiSwitch Manager.
Fortinet has provided a list of affected product versions and the necessary upgrades to mitigate the issue. These upgrades are scheduled for release as of January 27, 2026.
Product Affected Versions Solution
FortiAnalyzer 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above FortiAnalyzer 7.4 7.4.0 through 7.4.9 Upgrade to 7.4.10 or above FortiAnalyzer 7.2 7.2.0 through 7.2.11 Upgrade to 7.2.12 or above FortiAnalyzer 7.0 7.0.0 through 7.0.15 Upgrade to 7.0.16 or above FortiAnalyzer 6.4 Not affected N/A FortiManager 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above FortiManager 7.4 7.4.0 through 7.4.9 Upgrade to 7.4.10 or above FortiManager 7.2 7.2.0 through 7.2.11 Upgrade to 7.2.13 or above FortiManager 7.0 7.0.0 through 7.0.15 Upgrade to 7.0.16 or above FortiManager 6.4 Not affected N/A FortiOS 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above FortiOS 7.4 7.4.0 through 7.4.10 Upgrade to 7.4.11 or above FortiOS 7.2 7.2.0 through 7.2.12 Upgrade to 7.2.13 or above FortiOS 7.0 7.0.0 through 7.0.18 Upgrade to 7.0.19 or above FortiOS 6.4 Not affected N/A FortiProxy 7.6 7.6.0 through 7.6.4 Upgrade to 7.6.6 or above FortiProxy 7.4 7.4.0 through 7.4.12 Upgrade to 7.4.13 or above FortiProxy 7.2 All versions Migrate to fixed release FortiProxy 7.0 All versions Migrate to fixed release
Attackers can leverage this vulnerability to gain administrative access to targeted devices, including those with previous patches.
Fortinet customers are advised to use the upgrade tool to determine the appropriate upgrade paths.
Attackers utilized specific FortiCloud accounts, IP addresses, and post-exploitation methods. Fortinet recommends analyzing logs and administrative accounts for these indicators.
Category Indicators of Compromise (IoCs)
SSO User Accounts cloud-noc@mail[.]io, cloud-init@mail[.]io IP Addresses (Primary) 104.28.244[.]115, 104.28.212[.]114, 104.28.212[.]115, 104.28.195[.]105, 104.28.195[.]106, 104.28.227[.]106, 104.28.227[.]105, 104.28.244[.]114 IP Addresses (Other) 37.1.209[.]19, 217.119.139[.]50 Malicious Local Admins audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system
Key log patterns include successful SSO logins from suspicious IPs and the creation of admin accounts. Post-breach activities involved downloading configurations and adding backdoor admins.
On January 22, 2026, Fortinet identified and locked malicious accounts. The FortiCloud SSO was disabled server-side on January 26 and reinstated on January 27 with restrictions on vulnerable devices. A PSIRT advisory, FG-IR-26-060, was released on the same day.
For immediate security, Fortinet suggests limiting admin access to trusted IPs and disabling FortiCloud SSO if necessary. Commands for FortiOS/FortiProxy: config system global; set admin-forticloud-sso-login disable; end . For FortiManager/FortiAnalyzer: config system saml; set forticloud-sso disable; end .
Post-compromise steps include upgrading firmware, restoring clean configurations, rotating credentials, and auditing VPN/LDAP connections. Users are encouraged to monitor Fortinet PSIRT for further updates.
Based on reporting by Cyber Security News.
