Fortinet Blocks Exploited FortiCloud SSO Zero-Day Vulnerability CVE-2026-24858
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Fortinet has identified a critical vulnerability in its FortiCloud SSO system, known as CVE-2026-24858, which allows attackers to bypass authentication and gain administrative access to devices such as FortiOS, FortiManager, and FortiAnalyzer. This vulnerability was actively exploited, with reports of compromised FortiGate firewalls starting on January 21, where attackers created unauthorized local administrator accounts using FortiCloud SSO.
Initially, the attacks were thought to be a continuation of exploitation of a previously patched vulnerability, CVE-2025-59718. However, Fortinet confirmed on January 23 that an alternate authentication path was being exploited, even on fully patched systems. This indicates a serious oversight in the security of Fortinet’s SSO implementation.
Fortinet’s Chief Information Security Officer, Carl Windsor, noted that the exploitation was observed through specific FortiCloud SSO accounts, which were subsequently locked out. The attackers were able to log in using the email addresses cloud-init@mail.io and cloud-noc@mail.io, creating new admin accounts and exfiltrating firewall configurations.
In response to the ongoing threat, Fortinet has implemented several mitigation measures, including disabling the compromised FortiCloud accounts and blocking SSO connections from vulnerable devices. As of January 26, Fortinet disabled FortiCloud SSO globally to prevent further abuse, restoring limited access on January 27.
While Fortinet has stated that the vulnerability primarily affects FortiCloud SSO, it has warned that similar issues could arise in other SAML-based SSO implementations. This highlights the need for organizations to remain vigilant regarding their SSO configurations and access controls.
Fortinet is currently developing patches for affected products, including FortiOS, FortiManager, and FortiAnalyzer. Until these patches are released, Fortinet recommends that customers restrict administrative access and consider disabling FortiCloud SSO to enhance security.
- cloud-init@mail.io – One of the malicious accounts used to exploit the vulnerability.
- cloud-noc@mail.io – Another account involved in the attacks.
- FortiOS – The operating system affected by the vulnerability.
- FortiManager – Affected management solution for Fortinet devices.
- FortiAnalyzer – Another impacted product in Fortinet’s suite.
- CVE-2025-59718 – A previously exploited vulnerability related to FortiCloud SSO.
- FortiGate – The firewalls that were reported compromised during the attacks.
Key Takeaways
- Review your Fortinet device configurations to ensure that FortiCloud SSO is disabled if not needed.
- Monitor logs for unusual activity, especially for unauthorized admin account creation.
- Restrict administrative access to your Fortinet devices to trusted personnel only.
- Prepare to rotate all credentials and restore configurations from known-clean backups if compromise is suspected.
- Stay updated on Fortinet’s patch releases and apply them as soon as they are available.
Key Terms & Concepts
- CVE-2026-24858: In this article, CVE-2026-24858 refers to a critical vulnerability in Fortinet’s FortiCloud SSO that allows authentication bypass.
- FortiCloud SSO: FortiCloud SSO is a single sign-on service provided by Fortinet that allows users to access multiple Fortinet products with one set of credentials.
- FortiGate: FortiGate refers to Fortinet’s line of firewalls that were reported compromised due to the vulnerability.
- SAML: SAML stands for Security Assertion Markup Language, a standard for exchanging authentication and authorization data between parties.
- authentication bypass: Authentication bypass is a security flaw that allows unauthorized users to gain access to systems without proper credentials.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.