SecPod

Learn Search

Search across all Learn content

← Back to Security Research
From SSO to SOS: How CVE-2026-24858 Gave Hackers the Keys to Your Fortinet Gear

From SSO to SOS: How CVE-2026-24858 Gave Hackers the Keys to Your Fortinet Gear

Fortinet has addressed a critical authentication bypass vulnerability, CVE-2026-24858, affecting FortiOS, FortiManager, FortiAnalyzer, FortiWeb and FortiProxy. The vulnerability, with a CVSS score of 9.4, is actively exploited in the wild, making it crucial for organizations to apply the necessary p...

Jan 28, 2026By Santosh Sethuraman3 min read

Fortinet has addressed a critical authentication bypass vulnerability, CVE-2026-24858, affecting FortiOS, FortiManager, FortiAnalyzer, FortiWeb and FortiProxy. The vulnerability, with a CVSS score of 9.4, is actively exploited in the wild, making it crucial for organizations to apply the necessary patches immediately. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this CVE to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the urgency for Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by January 30, 2026.

Root Cause and Exploitation

The root cause of CVE-2026-24858 is classified as an “Authentication Bypass Using an Alternate Path or Channel” (CWE-288). The flaw exists within the FortiCloud Single Sign-On (SSO) login mechanism. While this feature is not enabled by default, it is automatically activated when an administrator registers a device to FortiCare via the GUI, unless the “Allow administrative login using FortiCloud SSO” option is explicitly disabled.

Attackers exploit this vulnerability by leveraging a “new attack path” that enables them to obtain SSO logins without valid authentication credentials. Specifically, an attacker with their own FortiCloud account and a registered device can log into other devices registered to entirely different accounts, provided those target devices have FortiCloud SSO enabled. Once inside, threat actors have been observed using two malicious accounts, [email protected] and [email protected], to automate the creation of local admin accounts for persistence, modify configurations to grant VPN access, and exfiltrate sensitive firewall configuration files.

Affected Products

According to the Fortinet PSIRT Advisory FG-IR-26-060, the following products and versions are affected:

ProductAffected Versions
FortiOS7.6.0 through 7.6.5, 7.4.0 through 7.4.10, 7.2.0 through 7.2.12, 7.0.0 through 7.0.18
FortiManager7.6.0 through 7.6.5, 7.4.0 through 7.4.9, 7.2.0 through 7.2.11, 7.0.0 through 7.0.15
FortiAnalyzer7.6.0 through 7.6.5, 7.4.0 through 7.4.9, 7.2.0 through 7.2.11, 7.0.0 through 7.0.15
FortiProxy7.4.0 through 7.4.5, 7.2.0 through 7.2.13, 7.0.0 through 7.0.19
FortiWeb7.4.0 through 7.4.11, 7.6.0 through 7.6.6, 8.0.0 through 8.0.3
FortiSwitch ManagerUnder Investigation

Tactics, Techniques, and Procedures (TTPs)

The exploitation of this vulnerability and subsequent post-compromise activity involve multiple MITRE ATT&CK tactics. Attackers have been observed using automated scripts to perform rapid configuration exports and account creations.

TacticTactic IDTechniqueTechnique ID
PersistenceTA0003Valid Accounts; Boot or Logon Autostart Execution: Registry Run KeysT1078; T1547.001
Privilege EscalationTA0004Exploitation for Privilege EscalationT1068
Credential AccessTA0006Modify Authentication ProcessT1556
DiscoveryTA0007Data from Information RepositoriesT1213
ExecutionTA0002Command and Scripting InterpreterT1059
ExfiltrationTA0010Automated ExfiltrationT1020

Mitigation & Recommendations

To address CVE-2026-24858, Fortinet has released patches and implemented server-side restrictions. FortiOS 7.4.11 and subsequent releases for other products contain the necessary fixes.

On January 26, 2026, Fortinet temporarily disabled FortiCloud SSO globally and re-enabled it on January 27 with a block in place for any devices running vulnerable versions. Consequently, upgrading to the latest software versions is mandatory for FortiCloud SSO to function.

If you suspect a compromise, follow these steps:

  • Update Firmware: Immediately upgrade to the latest patched version.
  • Audit for Changes: Restore configurations from a known clean version and check for unauthorized admin accounts or VPN settings.
  • Credential Rotation: Rotate all credentials, including LDAP/AD accounts connected to FortiGate devices.
  • Restrict Access: Use local-in policies to limit administrative access to trusted IP addresses only.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

CVE Research

Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026

Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.

Sep 28, 2026