FortiCloud SSO Bypass (CVE-2026-24858): Active Exploitation and What You Need to Know
A critical authentication bypass in FortiCloud SSO (CVE-2026-24858, CVSS 9.4) is being actively exploited. Attackers with any FortiCloud account can potentially access devices belonging to other organizations. Patch immediately and audit your admin accounts.
TL;DR
A critical authentication bypass in FortiCloud SSO (CVE-2026-24858, CVSS 9.4) is being actively exploited. Attackers with any FortiCloud account can potentially access devices belonging to other organizations. Patch immediately and audit your admin accounts.
What Happened?
On January 27, 2026, Fortinet released an advisory for CVE-2026-24858—a critical vulnerability affecting FortiOS, FortiManager, FortiAnalyzer, and FortiProxy. The flaw allows authentication bypass through FortiCloud's single sign-on (SSO) feature.
In plain terms: if FortiCloud SSO is enabled on your device, an attacker with any FortiCloud account could potentially log into your device—even though their account has no legitimate relationship to your organization.
The vulnerability was being exploited in the wild before disclosure, with attackers using it to:
- Create persistent local admin accounts
- Download device configurations
- Configure unauthorized VPN access
Technical Details
CVE ID: CVE-2026-24858
CVSS Score: 9.4 (Critical)
CWE: CWE-288 (Authentication Bypass Using an Alternate Path or Channel)
Affected Products:
| Product | Affected Versions |
|---|---|
| FortiOS | 7.0.0–7.0.18, 7.2.0–7.2.12, 7.4.0–7.4.10, 7.6.0–7.6.5 |
| FortiManager | 7.0.0–7.0.15, 7.2.0–7.2.11, 7.4.0–7.4.9, 7.6.0–7.6.5 |
| FortiAnalyzer | 7.0.0–7.0.15, 7.2.0–7.2.11, 7.4.0–7.4.9, 7.6.0–7.6.5 |
| FortiProxy | 7.0.x, 7.2.x, 7.4.0–7.4.12, 7.6.0–7.6.4 |
Note: FortiCloud SSO is not enabled by default. However, it gets enabled automatically when registering a device through the GUI—unless the administrator explicitly disables the "Allow administrative login using FortiCloud SSO" toggle.
Observed Attack Pattern
Based on Fortinet's analysis and third-party observations, the attack follows this pattern:
- Initial Access: Attacker authenticates via FortiCloud SSO using their own credentials
- Persistence: Creates local admin account (common names: audit, backup, itadmin, secadmin, support, svcadmin, system)
- Exfiltration: Downloads device configuration
- Lateral Movement Prep: Configures VPN access for future entry
Indicators of Compromise
Known Malicious Accounts:
Associated IP Addresses:
- 104.28.244.115, 104.28.212.114, 104.28.212.115
- 104.28.195.105, 104.28.195.106
- 104.28.227.105, 104.28.227.106
- 104.28.244.114
- 37.1.209.19 (third-party reported)
- 217.119.139.50 (third-party reported)
Suspicious Admin Account Names:
audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system
Response Timeline
| Date | Action |
|---|---|
| Jan 22, 2026 | Fortinet locks malicious FortiCloud accounts |
| Jan 26, 2026 | FortiCloud SSO disabled globally (server-side) |
| Jan 27, 2026 | FortiCloud SSO re-enabled; vulnerable versions blocked |
| Jan 27, 2026 | Public advisory released (FG-IR-26-060) |
| Jan 27, 2026 | Added to CISA KEV catalog |
| Jan 30, 2026 | CISA remediation deadline for federal agencies |
Recommended Actions
Immediate Steps:
- Patch — Upgrade to fixed versions per Fortinet's advisory
- Audit Admin Accounts — Review all local admin accounts for unexpected entries
- Check Configurations — Compare current config against known-good backups
- Rotate Credentials — Change passwords for any LDAP/AD accounts connected to affected devices
- Review Logs — Look for SSO authentication from unknown sources or at unusual times
If You Suspect Compromise:
Fortinet recommends treating the device as potentially breached:
- Restore configuration from a verified clean backup
- Rotate all connected credentials
- Monitor for follow-on activity through established VPN tunnels
Lessons Learned
This vulnerability highlights several important points:
1. Cloud-integrated features expand attack surface. FortiCloud SSO is convenient—but it also means your device's security is partially dependent on Fortinet's cloud infrastructure and the integrity of the broader FortiCloud ecosystem.
2. Default-on features after registration can surprise you. The SSO feature enables during GUI-based registration unless explicitly disabled. Many organizations may not realize it's active.
3. Exploitation timelines are shrinking. The gap between vulnerability discovery and active exploitation continues to narrow. Organizations that learn about critical CVEs through news articles are often already behind.
Stay Ahead
Critical vulnerabilities like CVE-2026-24858 drop without warning. The organizations that respond fastest are the ones with systems in place to catch these disclosures the moment they happen—not hours or days later.
If today's news caught you off guard, it might be worth thinking about how you're tracking vulnerabilities that affect your specific infrastructure.
Track CVE-2026-24858 and get notified of updates:
View CVE-2026-24858 on VulnTracker →