Fortinet says attackers are actively exploiting CVE-2026-24858 to gain administrative access via FortiCloud SSO. Fortinet confirmed active exploitation of an authentication bypass flaw in FortiCloud SSO that could lead to administrative takeover of affected systems. Inside the Fortinet FortiCloud SSO FlawThe vulnerability, tracked as CVE-2026-24858, affects FortiOS, FortiManager, FortiAnalyzer, and FortiProxy and carries a CVSS score of 9.4. Although FortiCloud SSO is not enabled by default, it is automatically activated during FortiCare registration through the GUI unless administrators explicitly disable the option to allow administrative login using FortiCloud SSO. FortiCloud SSO is intended to simplify administration by allowing users to authenticate to Fortinet devices using FortiCloud credentials.