SecPod

Learn Search

Search across all Learn content

← Back to Security Research
From SSO to SOS: How CVE-2026-24858 Gave Hackers the Keys to Your Fortinet Gear

From SSO to SOS: How CVE-2026-24858 Gave Hackers the Keys to Your Fortinet Gear

Fortinet has addressed a critical authentication bypass vulnerability, CVE-2026-24858, affecting FortiOS, FortiManager, FortiAnalyzer, FortiWeb and FortiProxy. The vulnerability, with a CVSS score of 9.4, is actively exploited in the wild, making it crucial for organizations to apply the necessary p...

Jan 28, 2026By Santosh Sethuraman3 min read

Fortinet has addressed a critical authentication bypass vulnerability, CVE-2026-24858, affecting FortiOS, FortiManager, FortiAnalyzer, FortiWeb and FortiProxy. The vulnerability, with a CVSS score of 9.4, is actively exploited in the wild, making it crucial for organizations to apply the necessary patches immediately. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this CVE to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing the urgency for Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by January 30, 2026.

Root Cause and Exploitation

The root cause of CVE-2026-24858 is classified as an “Authentication Bypass Using an Alternate Path or Channel” (CWE-288). The flaw exists within the FortiCloud Single Sign-On (SSO) login mechanism. While this feature is not enabled by default, it is automatically activated when an administrator registers a device to FortiCare via the GUI, unless the “Allow administrative login using FortiCloud SSO” option is explicitly disabled.

Attackers exploit this vulnerability by leveraging a “new attack path” that enables them to obtain SSO logins without valid authentication credentials. Specifically, an attacker with their own FortiCloud account and a registered device can log into other devices registered to entirely different accounts, provided those target devices have FortiCloud SSO enabled. Once inside, threat actors have been observed using two malicious accounts, [email protected] and [email protected], to automate the creation of local admin accounts for persistence, modify configurations to grant VPN access, and exfiltrate sensitive firewall configuration files.

Affected Products

According to the Fortinet PSIRT Advisory FG-IR-26-060, the following products and versions are affected:

Tactics, Techniques, and Procedures (TTPs)

The exploitation of this vulnerability and subsequent post-compromise activity involve multiple MITRE ATT&CK tactics. Attackers have been observed using automated scripts to perform rapid configuration exports and account creations.

Mitigation & Recommendations

To address CVE-2026-24858, Fortinet has released patches and implemented server-side restrictions. FortiOS 7.4.11 and subsequent releases for other products contain the necessary fixes.

On January 26, 2026, Fortinet temporarily disabled FortiCloud SSO globally and re-enabled it on January 27 with a block in place for any devices running vulnerable versions. Consequently, upgrading to the latest software versions is mandatory for FortiCloud SSO to function.

If you suspect a compromise, follow these steps:

  • Update Firmware: Immediately upgrade to the latest patched version.
  • Audit for Changes: Restore configurations from a known clean version and check for unauthorized admin accounts or VPN settings.
  • Credential Rotation: Rotate all credentials, including LDAP/AD accounts connected to FortiGate devices.
  • Restrict Access: Use local-in policies to limit administrative access to trusted IP addresses only.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores
StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

CVE Research

StyleSmuggler: Inside the Unpatched Magento Zero-Day Backdooring Live Stores

StyleSmuggler, an unpatched Magento and Adobe Commerce flaw letting attackers execute code without authentication via log poisoning, installing a persistent Linux backdoor that has already compromised live stores with no vendor patch available.

Sep 7, 2026

Open CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover
CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Vulnerability

CVE Research

CVE-2026-6471: 12-Year-Old PostgreSQL PostGREShell Flaw Enables Server Takeover

Sep 7, 2026

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026