None
EN
Fortinet Confirms CVE-2026-24858 SSO Flaw Under Active Attack
['Ken Underhill']
eSecurity Planet
Fortinet says attackers are actively exploiting CVE-2026-24858 to gain administrative access via FortiCloud SSO.
Fortinet confirmed active exploitation of an authentication bypass flaw in FortiCloud SSO that could lead to administrative takeover of affected systems.
Inside the Fortinet FortiCloud SSO FlawThe vulnerability, tracked as CVE-2026-24858, affects FortiOS, FortiManager, FortiAnalyzer, and FortiProxy and carries a CVSS score of 9.4.
Although FortiCloud SSO is not enabled by default, it is automatically activated during FortiCare registration through the GUI unless administrators explicitly disable the option to allow administrative login using FortiCloud SSO.
FortiCloud SSO is intended to simplify administration by allowing users to authenticate to Fortinet devices using FortiCloud credentials.
access
fortinet
forticloud
administrative
attackers
devices
authentication
vulnerability
configuration
nthe