Fortinet Discovers Critical CVE-2026-24858 Vulnerability in FortiCloud SSO
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Fortinet has revealed a serious vulnerability in its FortiCloud SSO service, designated as CVE-2026-24858, with a high severity score of 9.4. This authentication bypass flaw allows attackers with a FortiCloud account to log into devices registered to other accounts, provided specific conditions are met. The vulnerability was confirmed to have been exploited in the wild by two malicious FortiCloud accounts, which were blocked as of January 22.
Customers using FortiAnalyzer, FortiManager, FortiOS, and FortiProxy are directly affected and are advised to upgrade to the recommended versions to restore FortiCloud SSO services. Although some versions have safe releases available, patches for most affected products are still in development. The vulnerability was discovered after users reported compromises even after a patch was applied for earlier vulnerabilities.
Earlier vulnerabilities, CVE-2025-59718 and CVE-2025-59719, were patched in December, but attackers managed to bypass these fixes using alternate methods. The original attacks were first identified by Arctic Wolf around January 15, leading to further investigations into the security flaws.
Implications for Users and Organizations
This incident underscores the risks associated with SSO implementations, particularly those based on SAML. Carl Windsor, CISO at Fortinet, noted that while the attacks were specifically targeting FortiCloud SSO, all SAML-based SSO systems could be vulnerable. Organizations should be vigilant about their SSO configurations and consider disabling SSO features that are not essential.
Users should monitor their FortiCloud accounts closely for any unauthorized access and ensure that their devices are updated to the latest secure versions. The fact that the FortiCloud SSO login feature is not enabled by default is a crucial point; however, administrators may inadvertently enable it during device registration, which can expose them to risks.
As the situation develops, organizations should stay informed about updates from Fortinet and apply patches as they become available. This incident serves as a reminder of the importance of maintaining robust security practices and regularly reviewing configurations to mitigate potential vulnerabilities.
Key Takeaways
- Monitor FortiCloud accounts for any unauthorized access or suspicious activity.
- Upgrade affected products like FortiAnalyzer, FortiManager, FortiOS, and FortiProxy to the recommended secure versions.
- Disable FortiCloud SSO login features if they are not necessary for your operations.
- Stay updated on Fortinet’s advisories and apply patches as they are released.
- Review and strengthen SSO configurations to prevent potential exploitation.
Key Terms & Concepts
- CVE-2026-24858: In this article, CVE-2026-24858 refers to a critical authentication bypass vulnerability in FortiCloud SSO.
- SAML: SAML stands for Security Assertion Markup Language, a standard for exchanging authentication and authorization data between parties.
- FortiCloud: FortiCloud is a cloud-based service provided by Fortinet for managing security services and devices.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.