Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Fortinet Disables FortiCloud SSO Following 0-day Vulnerability Exploited in the Wild

Fortinet has temporarily disabled its FortiCloud Single Sign-On (SSO) service following the identification of an exploited zero-day authentication bypass vulnerability across multiple products.

Fortinet has temporarily disabled its FortiCloud Single Sign-On (SSO) service following the identification of an exploited zero-day authentication bypass vulnerability across multiple products.

This vulnerability, referred to as FG-IR-26-060, enables attackers with a malicious FortiCloud account to access devices registered under different accounts. It involves an authentication bypass using an alternate path or channel vulnerability (CWE-288) and impacts FortiOS, FortiManager, and FortiAnalyzer when FortiCloud SSO is activated. This feature is not enabled by default.

Attackers can leverage this vulnerability to gain administrative access to targeted devices, including those with previous patches. While all SAML SSO implementations are affected, exploitation has been primarily observed in FortiCloud SSO. Investigations continue for FortiWeb and FortiSwitch Manager.

Fortinet has provided a list of affected product versions and the necessary upgrades to mitigate the issue. These upgrades are scheduled for release as of January 27, 2026.

Product Affected Versions Solution

FortiAnalyzer 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above FortiAnalyzer 7.4 7.4.0 through 7.4.9 Upgrade to 7.4.10 or above FortiAnalyzer 7.2 7.2.0 through 7.2.11 Upgrade to 7.2.12 or above FortiAnalyzer 7.0 7.0.0 through 7.0.15 Upgrade to 7.0.16 or above FortiAnalyzer 6.4 Not affected N/A FortiManager 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above FortiManager 7.4 7.4.0 through 7.4.9 Upgrade to 7.4.10 or above FortiManager 7.2 7.2.0 through 7.2.11 Upgrade to 7.2.13 or above FortiManager 7.0 7.0.0 through 7.0.15 Upgrade to 7.0.16 or above FortiManager 6.4 Not affected N/A FortiOS 7.6 7.6.0 through 7.6.5 Upgrade to 7.6.6 or above FortiOS 7.4 7.4.0 through 7.4.10 Upgrade to 7.4.11 or above FortiOS 7.2 7.2.0 through 7.2.12 Upgrade to 7.2.13 or above FortiOS 7.0 7.0.0 through 7.0.18 Upgrade to 7.0.19 or above FortiOS 6.4 Not affected N/A FortiProxy 7.6 7.6.0 through 7.6.4 Upgrade to 7.6.6 or above FortiProxy 7.4 7.4.0 through 7.4.12 Upgrade to 7.4.13 or above FortiProxy 7.2 All versions Migrate to fixed release FortiProxy 7.0 All versions Migrate to fixed release

Attackers can leverage this vulnerability to gain administrative access to targeted devices, including those with previous patches.
Noah Kensington · Thehackingpost

Fortinet customers are advised to use the upgrade tool to determine the appropriate upgrade paths.

Attackers utilized specific FortiCloud accounts, IP addresses, and post-exploitation methods. Fortinet recommends analyzing logs and administrative accounts for these indicators.

Category Indicators of Compromise (IoCs)

SSO User Accounts cloud-noc@mail[.]io, cloud-init@mail[.]io IP Addresses (Primary) 104.28.244[.]115, 104.28.212[.]114, 104.28.212[.]115, 104.28.195[.]105, 104.28.195[.]106, 104.28.227[.]106, 104.28.227[.]105, 104.28.244[.]114 IP Addresses (Other) 37.1.209[.]19, 217.119.139[.]50 Malicious Local Admins audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system

Advertisement

Key log patterns include successful SSO logins from suspicious IPs and the creation of admin accounts. Post-breach activities involved downloading configurations and adding backdoor admins.

On January 22, 2026, Fortinet identified and locked malicious accounts. The FortiCloud SSO was disabled server-side on January 26 and reinstated on January 27 with restrictions on vulnerable devices. A PSIRT advisory, FG-IR-26-060, was released on the same day.

For immediate security, Fortinet suggests limiting admin access to trusted IPs and disabling FortiCloud SSO if necessary. Commands for FortiOS/FortiProxy: config system global; set admin-forticloud-sso-login disable; end . For FortiManager/FortiAnalyzer: config system saml; set forticloud-sso disable; end .

Post-compromise steps include upgrading firmware, restoring clean configurations, rotating credentials, and auditing VPN/LDAP connections. Users are encouraged to monitor Fortinet PSIRT for further updates.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories