cbcvebase.
CVE-2026-24858
published 2026-01-27

CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-01-30
Exploited in the wild
EPSS
85.84%
99.7th percentile
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
fortinetfortianalyzer
fortinetfortianalyzer7.0.0 – 7.0.15
fortinetfortianalyzer7.2.0 – 7.2.11
fortinetfortianalyzer>= 7.4.0 < 7.4.107.4.10
fortinetfortianalyzer7.4.0 – 7.4.9
fortinetfortianalyzer>= 7.6.0 < 7.6.67.6.6
fortinetfortianalyzer7.6.0 – 7.6.5
fortinetforticloud
fortinetfortimanager
fortinetfortimanager7.0.0 – 7.0.15
fortinetfortimanager7.2.0 – 7.2.11
fortinetfortimanager>= 7.4.0 < 7.4.107.4.10
fortinetfortimanager7.4.0 – 7.4.9
fortinetfortimanager>= 7.6.0 < 7.6.67.6.6
fortinetfortimanager7.6.0 – 7.6.5
fortinetfortinac-f>= 7.6.3 < 7.6.67.6.6
fortinetfortinac-f7.6.3 – 7.6.5
fortinetfortinet
fortinetfortios
fortinetfortios7.0.0 – 7.0.18
fortinetfortios7.2.0 – 7.2.12
fortinetfortios>= 7.4.0 < 7.4.117.4.11
fortinetfortios7.4.0 – 7.4.10
fortinetfortios>= 7.6.0 < 7.6.67.6.6
fortinetfortios7.6.0 – 7.6.5

Detection & IOCsextracted from sources · hover to see the quote

ip104.28.244.115
ip104.28.212.114
ip104.28.212.115
ip104.28.195.105
ip37.1.209.19
ip217.119.139.50
ip193.24.211.61
ip185.156.73.62
ip185.242.246.127
ip172.67.196.232
domainndibstersoft.com
domainneremedysoft.com
urlhxxps://storage.googleapis[.]com/apply-main/windows_agent_x64[.]msi
urlhxxps://fastdlvrss[.]s3[.]us-east-1[.]amazonaws[.]com/paswr.zip
domainfastdlvrss.s3.us-east-1.amazonaws.com
pathC:\ProgramData\USOShared
filenameSysdmupd.zip
filenamejava.exe
commandconfig system global set admin-forticloud-sso-login disable end
processWIN-X8WRBOSK0OF
processWIN-YRSXLEONJY2
processWIN-1J7L3SQSTMS
  • Hunt for creation of any of the following local admin account names on FortiGate/FortiOS/FortiManager/FortiAnalyzer devices, as these were created by attackers post-exploitation: audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system
  • Alert on FortiCloud SSO logins using the email addresses [email protected] or [email protected], which are confirmed malicious attacker-controlled accounts used in active exploitation.
  • Attacks appeared automated: new rogue admin and VPN-enabled accounts were created and firewall configurations exfiltrated within seconds of initial access via FortiCloud SSO.
  • Monitor for the FortiGate agent process 'fortidcagent' as an indicator of attacker activity on compromised appliances.
  • Alert on PowerShell commands downloading from fastdlvrss.s3.us-east-1.amazonaws.com and dropping files to C:\ProgramData\USOShared, followed by execution of java.exe from that path.
  • Check for the scheduled task name 'MeshUserTask' and registry key 'JavaMainUpdate' as persistence mechanisms dropped post-FortiGate compromise.
  • Monitor for NTDS.dit access and makecab usage following FortiGate VPN-assigned IP range logins, indicating credential harvesting after exploitation.
  • FortiCloud SSO is automatically enabled when a device is registered with FortiCare unless manually disabled; audit all devices for this setting as it is the attack vector.
  • GreyNoise observed only one day of pre-disclosure scanning activity for CVE-2026-24858 (CVSS 9.4), indicating extremely compressed warning time; treat any Fortinet-targeted scanning spikes as high-priority.
  • ·The vulnerability only applies when FortiCloud SSO authentication is enabled on the device. Devices with FortiCloud SSO disabled are not exploitable via this specific path.
  • ·While only FortiCloud SSO exploitation has been observed in the wild, Fortinet warns the issue applies to ALL SAML SSO implementations, not just FortiCloud.
  • ·Fortinet was still investigating whether FortiWeb and FortiSwitch Manager are affected at time of initial advisory publication.
  • ·Customers who detect the listed IOCs in their logs should treat their devices as fully compromised and review all administrator accounts, restore configurations from known-clean backups, and rotate all credentials.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.