FortiCloud SSO Bypass (CVE-2026-24858): Active Exploitation and What You Need to Know

A critical authentication bypass in FortiCloud SSO (CVE-2026-24858, CVSS 9.4) is being actively exploited. Attackers with any FortiCloud account can potentially access devices belonging to other organizations. Patch immediately and audit your admin accounts.

TL;DR

A critical authentication bypass in FortiCloud SSO (CVE-2026-24858, CVSS 9.4) is being actively exploited. Attackers with any FortiCloud account can potentially access devices belonging to other organizations. Patch immediately and audit your admin accounts.


What Happened?

On January 27, 2026, Fortinet released an advisory for CVE-2026-24858—a critical vulnerability affecting FortiOS, FortiManager, FortiAnalyzer, and FortiProxy. The flaw allows authentication bypass through FortiCloud's single sign-on (SSO) feature.

In plain terms: if FortiCloud SSO is enabled on your device, an attacker with any FortiCloud account could potentially log into your device—even though their account has no legitimate relationship to your organization.

The vulnerability was being exploited in the wild before disclosure, with attackers using it to:

  • Create persistent local admin accounts
  • Download device configurations
  • Configure unauthorized VPN access

Technical Details

CVE ID: CVE-2026-24858
CVSS Score: 9.4 (Critical)
CWE: CWE-288 (Authentication Bypass Using an Alternate Path or Channel)

Affected Products:

Product Affected Versions
FortiOS 7.0.0–7.0.18, 7.2.0–7.2.12, 7.4.0–7.4.10, 7.6.0–7.6.5
FortiManager 7.0.0–7.0.15, 7.2.0–7.2.11, 7.4.0–7.4.9, 7.6.0–7.6.5
FortiAnalyzer 7.0.0–7.0.15, 7.2.0–7.2.11, 7.4.0–7.4.9, 7.6.0–7.6.5
FortiProxy 7.0.x, 7.2.x, 7.4.0–7.4.12, 7.6.0–7.6.4

Note: FortiCloud SSO is not enabled by default. However, it gets enabled automatically when registering a device through the GUI—unless the administrator explicitly disables the "Allow administrative login using FortiCloud SSO" toggle.


Observed Attack Pattern

Based on Fortinet's analysis and third-party observations, the attack follows this pattern:

  1. Initial Access: Attacker authenticates via FortiCloud SSO using their own credentials
  2. Persistence: Creates local admin account (common names: audit, backup, itadmin, secadmin, support, svcadmin, system)
  3. Exfiltration: Downloads device configuration
  4. Lateral Movement Prep: Configures VPN access for future entry

Indicators of Compromise

Known Malicious Accounts:

  • [email protected]
  • [email protected]

Associated IP Addresses:

  • 104.28.244.115, 104.28.212.114, 104.28.212.115
  • 104.28.195.105, 104.28.195.106
  • 104.28.227.105, 104.28.227.106
  • 104.28.244.114
  • 37.1.209.19 (third-party reported)
  • 217.119.139.50 (third-party reported)

Suspicious Admin Account Names:

audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system


Response Timeline

Date Action
Jan 22, 2026 Fortinet locks malicious FortiCloud accounts
Jan 26, 2026 FortiCloud SSO disabled globally (server-side)
Jan 27, 2026 FortiCloud SSO re-enabled; vulnerable versions blocked
Jan 27, 2026 Public advisory released (FG-IR-26-060)
Jan 27, 2026 Added to CISA KEV catalog
Jan 30, 2026 CISA remediation deadline for federal agencies

Recommended Actions

Immediate Steps:

  1. Patch — Upgrade to fixed versions per Fortinet's advisory
  2. Audit Admin Accounts — Review all local admin accounts for unexpected entries
  3. Check Configurations — Compare current config against known-good backups
  4. Rotate Credentials — Change passwords for any LDAP/AD accounts connected to affected devices
  5. Review Logs — Look for SSO authentication from unknown sources or at unusual times

If You Suspect Compromise:

Fortinet recommends treating the device as potentially breached:

  • Restore configuration from a verified clean backup
  • Rotate all connected credentials
  • Monitor for follow-on activity through established VPN tunnels

Lessons Learned

This vulnerability highlights several important points:

1. Cloud-integrated features expand attack surface. FortiCloud SSO is convenient—but it also means your device's security is partially dependent on Fortinet's cloud infrastructure and the integrity of the broader FortiCloud ecosystem.

2. Default-on features after registration can surprise you. The SSO feature enables during GUI-based registration unless explicitly disabled. Many organizations may not realize it's active.

3. Exploitation timelines are shrinking. The gap between vulnerability discovery and active exploitation continues to narrow. Organizations that learn about critical CVEs through news articles are often already behind.


Stay Ahead

Critical vulnerabilities like CVE-2026-24858 drop without warning. The organizations that respond fastest are the ones with systems in place to catch these disclosures the moment they happen—not hours or days later.

If today's news caught you off guard, it might be worth thinking about how you're tracking vulnerabilities that affect your specific infrastructure.

Track CVE-2026-24858 and get notified of updates:
View CVE-2026-24858 on VulnTracker →