Skip to content

Security1 publisher2 min readPublished

CVE-2026-24858 let attackers log into Fortinet devices registered to other customers

Fortinet switched off FortiCloud SSO worldwide on January 26 and turned it back on the next day with server-side changes. Devices already fully patched against the two 2025 SAML bypasses were compromised anyway.

The Watch · Security desk

Illustration accompanying CVE-2026-24858 let attackers log into Fortinet devices registered to other customers

What happened

  • CVE-2026-24858 lets anyone with a FortiCloud account and one registered device log in to devices registered to other customers across FortiOS, FortiManager, FortiWeb, FortiProxy and FortiAnalyzer where FortiCloud SSO is enabled.
  • CISA added CVE-2026-24858 to the Known Exploited Vulnerabilities catalog on January 27, 2026 and published guidance the following day.
  • The bug is the third disclosed FortiCloud SSO authentication bypass, after CVE-2025-59718 and CVE-2025-59719 in 2025.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint An inventory report showing every device on the release that fixed the SAML bypasses does not answer the question here, because the new flaw sits in a different weakness class and reached those devices anyway.
  • exposure The trust boundary is Fortinet's SSO service, so one attacker-controlled FortiCloud tenant with a single registered device becomes a login path into other customers' firewalls, managers and analyzers.
  • decision Operators now choose between keeping FortiCloud SSO enabled and turning it off, and either way they have to find the accounts and VPN entries added before January 27.
  • precedent Three bypasses of the same authentication path within 50 days of the December advisory sets the expectation that the FortiCloud SSO route keeps attracting research, and that the next fix may again arrive on Fortinet's side of the connection.

The two 2025 bugs were signature problems. CVE-2025-59718 and CVE-2025-59719 are classified CWE-347, improper verification of a cryptographic signature, and were abused with a crafted SAML message [4]. CVE-2026-24858 is CWE-288, authentication bypass using an alternate path or channel [1]. Different weakness class, different code path, so the release that fixed the SAML handling left the new route open [4]. Fortinet observed the malicious activity on devices that had been fully upgraded at the time of exploitation [5].

An attacker needs a FortiCloud account and one registered device of their own. From there they can log in to devices registered to other users wherever FortiCloud SSO is enabled [2].

The affected product list also moved: FortiManager and FortiAnalyzer are in scope for the new bug and were not in the earlier advisory, while FortiSwitch Manager appears only in the 2025 pair [1].

Arctic Wolf Labs posted its observation of malicious configuration changes on FortiGate devices via SSO accounts on January 21 [12]. Fortinet's Carl Windsor published "Analysis of Single Sign-On Abuse on FortiOS" on January 22 [13]. Fortinet disabled all FortiCloud SSO authentication on January 26 and reinstated it on January 27 with changes to prevent exploitation of vulnerable devices, according to the company [6]. CISA added the CVE to the Known Exploited Vulnerabilities catalog the same day [7], six days after the Arctic Wolf post [3], and issued guidance on January 28 [9]. The advisory that covered the first two bypasses, FG-IR-25-647, was last modified on December 9, 2025, fifty days before that guidance [11][2].

What the January 27 change does is stop further exploitation of vulnerable devices [6]. Accounts created during the exploitation window, and the VPN configuration written to grant those accounts access, stay where they are until an operator removes them [7]. Fortinet reported three actions on upgraded devices: unauthorized firewall configuration changes on FortiGate, unauthorized account creation, and unauthorized VPN changes granting access to the new accounts [5].

CISA's instruction is to check for indicators of compromise on all internet-accessible affected Fortinet products and to apply updates immediately as soon as they are available, following Fortinet's instructions [8]. The wording puts the device-level patch in the future tense; the mitigation that is already in force was applied by Fortinet, not by customers [6]. Fortinet's advisory for the new bug, FG-IR-26-060, was last modified on January 27, the day the service came back and the day the CVE entered KEV [10][7].

What to watch

  • Whether device-level updates for CVE-2026-24858 ship, or Fortinet's January 27 server-side change remains the only fix for older releases.
  • Whether Arctic Wolf or Fortinet attribute the FortiGate configuration changes to a named group or campaign.
  • Whether intrusions surface on FortiManager and FortiAnalyzer, which carry access to downstream firewalls and to the logs of the intrusion itself.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories