CVE-2026-24858
published 2026-01-27CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-01-30
Exploited in the wild
EPSS
85.84%
99.7th percentile
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | 7.0.0 – 7.0.15 | — |
| fortinet | fortianalyzer | 7.2.0 – 7.2.11 | — |
| fortinet | fortianalyzer | >= 7.4.0 < 7.4.10 | 7.4.10 |
| fortinet | fortianalyzer | 7.4.0 – 7.4.9 | — |
| fortinet | fortianalyzer | >= 7.6.0 < 7.6.6 | 7.6.6 |
| fortinet | fortianalyzer | 7.6.0 – 7.6.5 | — |
| fortinet | forticloud | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | 7.0.0 – 7.0.15 | — |
| fortinet | fortimanager | 7.2.0 – 7.2.11 | — |
| fortinet | fortimanager | >= 7.4.0 < 7.4.10 | 7.4.10 |
| fortinet | fortimanager | 7.4.0 – 7.4.9 | — |
| fortinet | fortimanager | >= 7.6.0 < 7.6.6 | 7.6.6 |
| fortinet | fortimanager | 7.6.0 – 7.6.5 | — |
| fortinet | fortinac-f | >= 7.6.3 < 7.6.6 | 7.6.6 |
| fortinet | fortinac-f | 7.6.3 – 7.6.5 | — |
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 7.0.0 – 7.0.18 | — |
| fortinet | fortios | 7.2.0 – 7.2.12 | — |
| fortinet | fortios | >= 7.4.0 < 7.4.11 | 7.4.11 |
| fortinet | fortios | 7.4.0 – 7.4.10 | — |
| fortinet | fortios | >= 7.6.0 < 7.6.6 | 7.6.6 |
| fortinet | fortios | 7.6.0 – 7.6.5 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Hunt for creation of any of the following local admin account names on FortiGate/FortiOS/FortiManager/FortiAnalyzer devices, as these were created by attackers post-exploitation: audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system ↗
- →Alert on FortiCloud SSO logins using the email addresses [email protected] or [email protected], which are confirmed malicious attacker-controlled accounts used in active exploitation. ↗
- →Attacks appeared automated: new rogue admin and VPN-enabled accounts were created and firewall configurations exfiltrated within seconds of initial access via FortiCloud SSO. ↗
- →Monitor for the FortiGate agent process 'fortidcagent' as an indicator of attacker activity on compromised appliances. ↗
- →Alert on PowerShell commands downloading from fastdlvrss.s3.us-east-1.amazonaws.com and dropping files to C:\ProgramData\USOShared, followed by execution of java.exe from that path. ↗
- →Check for the scheduled task name 'MeshUserTask' and registry key 'JavaMainUpdate' as persistence mechanisms dropped post-FortiGate compromise. ↗
- →Monitor for NTDS.dit access and makecab usage following FortiGate VPN-assigned IP range logins, indicating credential harvesting after exploitation. ↗
- →FortiCloud SSO is automatically enabled when a device is registered with FortiCare unless manually disabled; audit all devices for this setting as it is the attack vector. ↗
- →GreyNoise observed only one day of pre-disclosure scanning activity for CVE-2026-24858 (CVSS 9.4), indicating extremely compressed warning time; treat any Fortinet-targeted scanning spikes as high-priority. ↗
- ·The vulnerability only applies when FortiCloud SSO authentication is enabled on the device. Devices with FortiCloud SSO disabled are not exploitable via this specific path. ↗
- ·While only FortiCloud SSO exploitation has been observed in the wild, Fortinet warns the issue applies to ALL SAML SSO implementations, not just FortiCloud. ↗
- ·Fortinet was still investigating whether FortiWeb and FortiSwitch Manager are affected at time of initial advisory publication. ↗
- ·Customers who detect the listed IOCs in their logs should treat their devices as fully compromised and review all administrator accounts, restore configurations from known-clean backups, and rotate all credentials. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM APE1808 Devices
cisa_ics·2026-03-12·CVSS 5.8
[MEDIUM] Siemens RUGGEDCOM APE1808 Devices
ICS Advisory
##
Siemens RUGGEDCOM APE1808 Devices
Release DateMarch 12, 2026
Alert CodeICSA-26-071-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Fortinet has published information on vulnerabilities in FORTIOS. This advisory lists the related Siemens Industrial products. Siemens has released a new version for RUGGEDCOM APE1808 and recommends to update to the latest version.
The following versions of Siemens RUGGEDCOM APE1808 Devices are affected:
- RUGGEDCOM APE1808 vers:all/*, vers:all/* (CVE-2026-24858, CVE-2025-55018, CVE-2025-62439, CVE-2025-64157)
CVSS
Vendor
Equipment
Vulnerabilities
| v3 9.8
| Siemens
| Siemens RUGGEDCOM APE1808 Devices
| Inconsistent Interpretation of HTTP Requests ('
Fortinet
Administrative FortiCloud SSO authentication bypass
vendor_fortinet·2026-01-27·CVSS 9.8
CVE-2026-24858 [CRITICAL] CWE-288 Administrative FortiCloud SSO authentication bypass
FG-IR-26-060: Administrative FortiCloud SSO authentication bypass
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may
CISA
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
cisa·2026-01-27·CVSS 9.8
CVE-2026-24858 [CRITICAL] CWE-288 Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Vulnerability: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Affected: Fortinet Multiple Products
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: Please adhere to Fortinet's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all inter
GHSA
GHSA-2x38-48vp-w23x: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7
ghsa_unreviewed·2026-01-27
CVE-2026-24858 [CRITICAL] CWE-288 GHSA-2x38-48vp-w23x: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
VulnCheck
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
vulncheck·2026·CVSS 9.8
CVE-2026-24858 [CRITICAL] CWE-288 Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Affected: Fortinet Multiple Products
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://fortiguard.fortinet.com/psirt/FG-IR-26-060; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabili
Elastic
FortiGate Administrator Account Creation from Unusual Source
elastic_rules·CVSS 9.8
CVE-2026-24858 [CRITICAL] FortiGate Administrator Account Creation from Unusual Source
FortiGate Administrator Account Creation from Unusual Source
This rule detects FortiGate administrator account creation from a source IP address not previously seen performing
admin operations on the device. Threat actors exploiting CVE-2026-24858 (FG-IR-26-060) authenticate via FortiCloud
SSO bypass and immediately create local administrator accounts for persistence, typically from infrastructure not
associated with normal administrative activity.
Query:
data_stream.dataset: "fortinet_fortigate.log" and
event.code: "0100044547" and
fortinet.firewall.cfgpath: "system.admin" and
fortinet.firewall.action: "Add" and
fortinet.firewall.ui: (* and not "")
Elastic
FortiGate Overly Permissive Firewall Policy Created
elastic_rules·CVSS 9.8
CVE-2026-24858 [CRITICAL] FortiGate Overly Permissive Firewall Policy Created
FortiGate Overly Permissive Firewall Policy Created
This rule detects the creation or modification of a FortiGate firewall policy that permits all sources, all
destinations, and all services. An overly permissive policy effectively bypasses all firewall protections. Threat actors
exploiting CVE-2026-24858 have been observed creating such policies to allow unrestricted traffic flow through
compromised FortiGate devices.
Query:
any where data_stream.dataset == "fortinet_fortigate.log" and
event.code == "0100044547" and
fortinet.firewall.cfgpath == "firewall.policy" and
fortinet.firewall.action in ("Add", "Edit") and
fortinet.firewall.cfgattr like~ "*srcaddr[all]*" and
fortinet.firewall.cfgattr like~ "*dstaddr[all]*" and
fortinet.firewall.cfgattr like~ "*service[all]*"
Elastic
FortiGate FortiCloud SSO Login from Unusual Source
elastic_rules·CVSS 9.8
CVE-2026-24858 [CRITICAL] FortiGate FortiCloud SSO Login from Unusual Source
FortiGate FortiCloud SSO Login from Unusual Source
This rule detects the first successful FortiCloud SSO login from a previously unseen source IP address to a FortiGate
device within the last 5 days. FortiCloud SSO logins from new source IPs may indicate exploitation of SAML-based
authentication bypass vulnerabilities such as CVE-2026-24858, where crafted SAML assertions allow unauthorized access to
FortiGate devices registered to other accounts. Environments that regularly use FortiCloud SSO will only alert on new
source IPs not seen in the lookback window.
Query:
FROM logs-fortinet_fortigate.* metadata _id, _version, _index
| WHERE data_stream.dataset == "fortinet_fortigate.log" and
event.category == "authentication" and event.action == "login" and
event.outcome == "success" and
(for
Elastic
FortiGate Configuration File Downloaded
elastic_rules·CVSS 9.8
CVE-2026-24858 [CRITICAL] FortiGate Configuration File Downloaded
FortiGate Configuration File Downloaded
This rule detects the download of a FortiGate device configuration file. Configuration exports contain sensitive data
including administrator password hashes, LDAP bind credentials, VPN pre-shared keys, routing tables, and firewall
policies. Threat actors exploiting CVE-2026-24858 have been observed exporting the full device configuration
immediately after gaining access to harvest credentials and map the internal network.
Query:
any where data_stream.dataset == "fortinet_fortigate.log" and
event.code == "0100032095" and
fortinet.firewall.action == "download"
No public exploits indexed.
Wiz
Agentless Threat Detection: Illuminating Cloud Blind Spots
blogs_wiz·2026-07-21·CVSS 9.8
CVE-2026-24858 [CRITICAL] Agentless Threat Detection: Illuminating Cloud Blind Spots
Virtual appliances play a critical role in cloud networks, providing services such as firewalls, secure gateways, and VPN connectivity. Yet, because they operate as "black boxes" that don't support traditional EDR agents, they have historically been a massive visibility gap for security teams. Over the past months, Wiz’s Agentless Workload Detection has fundamentally changed this pattern. Not only does it provide critical visibility into virtual appliances, but it also gives our research and IR teams the context needed to investigate activity associated with high-profile threat actors..This allows us to detect and analyze a wide array of sophisticated attacks, all without the need for agents.
In this blog post, we’ll show you a subset of the unique value this new capability has unlocked,
Qualys
FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
blogs_qualys·2026-07-08
CVE-2026-24858 FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices
## Table of Contents
Summary
What Happened
Who should pay attention
WhyIt Matters/ Potential Impact
Recommended Actions
CVEs and Affected Components
Exploitation Status / Threat Activity
Remediation Long Tail: Why Historical Exposure Persists
How Qualys Helps You Discover These Exposures
Use Qualys QueryLanguageto PrioritizeFortiBleedExposure
Detection and Threat Hunting Guidance
Conclusion
Contributor
Frequently Asked Questions (FAQs)
## Key Takeaways
FortiBleed refers to June 2026 public reporting of large-scale credential exposure and abuse targeting internet-reachable FortiGate management and SSL-VPN gateways driven by credential reuse and brute-force, not a single new zero-day.
Risk is highest for internet-exposed FortiGate devices without MFA, with reused or legacy-h
Hackernews
⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
blogs_hackernews·2026-06-22·CVSS 9.8
CVE-2026-24858 [CRITICAL] ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More
It’s Monday again.
This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control.
The annoying part is how little of this feels new. Weak credentials, sketchy downloads, browser extensions with too much access, and WordPress sites are used to push more attacks. Nothing clever. Just sloppy, cheap, and effective.
Here’s the Monday recap. Let’s get into the week’s mess.
## ⚡ Threat of the We
Greynoiseio
The Internet Changes Before the Advisory Drops
blogs_greynoiseio·2026-04-20·CVSS 4.9
CVE-2026-20127 [MEDIUM] The Internet Changes Before the Advisory Drops
Before Cisco published its advisory for CVE-2026-20127 — a CVSS 10.0 zero-day cited in a Five Eyes joint warning — GreyNoise sensors had already observed eight distinct surges of Cisco-targeting activity. The earliest arrived 39 days before disclosure. Each one came closer than the last. A new study finds this pattern is not an anomaly.
What the Data Shows
Over 103 days, GreyNoise tracked 147.8 million sessions across 276 vendor-specific tags covering 18 network infrastructure vendors. Of 104 detected surge events, 68 preceded a vendor-matched CVE — spanning 33 vulnerabilities across 16 vendor families. Statistical testing confirmed the pattern is not coincidence.
Median lead time: 11 days. 49% of surges arrived within 10 days of disclosure. 78% within 21 days.
Session volume is the
Bleepingcomputer
CISA orders feds to patch exploited Fortinet EMS flaw by Friday
blogs_bleepingcomputer·2026-04-06·CVSS 9.8
CVE-2026-35616 [CRITICAL] CISA orders feds to patch exploited Fortinet EMS flaw by Friday
## CISA orders feds to patch exploited Fortinet EMS flaw by Friday
## Sergiu Gatlan
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to secure FortiClient Enterprise Management Server (EMS) instances against an actively exploited vulnerability by Friday.
Tracked as CVE-2026-35616, this security flaw was discovered by cybersecurity firm Defused, which described it as a pre-authentication API access bypass that can allow attackers to bypass authentication and authorization controls entirely.
Fortinet released emergency hotfixes over the weekend to address the vulnerability and said the security issue stems from an improper access control weakness that unauthenticated attackers can exploit to execute code or commands via specially crafted requests.
Bleepingcomputer
Critical Fortinet Forticlient EMS flaw now exploited in attacks
blogs_bleepingcomputer·2026-03-30·CVSS 9.8
CVE-2026-21643 [CRITICAL] Critical Fortinet Forticlient EMS flaw now exploited in attacks
## Critical Fortinet Forticlient EMS flaw now exploited in attacks
## Sergiu Gatlan
Attackers are now actively exploiting a critical vulnerability in Fortinet's FortiClient EMS platform, according to threat intelligence company Defused.
Tracked as CVE-2026-21643 , this SQL injection vulnerability allows unauthenticated threat actors to execute arbitrary code or commands on unpatched systems through low-complexity attacks targeting the FortiClientEMS GUI (web interface) via maliciously crafted HTTP requests.
"Fortinet Forticlient EMS CVE-2026-21643 - currently marked as not exploited on CISA and other Known Exploited Vulnerabilities (KEV) lists - has seen first exploitation already 4 days ago according to our data," Defused warned over the weekend.
"Attackers can smuggle SQL statements
Sentinelone
FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
blogs_sentinelone·2026-03-10
FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
## Overview
Throughout early 2026, SentinelOne’s ® Digital Forensics & Incident Response (DFIR) team has responded to several incidents where FortiGate Next-Generation Firewall (NGFW) appliances have been compromised to establish a foothold into the targeted environment. Each incident was detected and stopped during the lateral movement phase of the attack.
Fortinet has disclosed and issued patches for several high-severity vulnerabilities allowing unauthorized access during the activity period of our investigations. Successful exploitation of these flaws allows an attacker to extract the configuration file from the FortiGate appliance, which frequently contains service account credentials and valuable network topology information for the targeted environment.
We observed a consistent t
Sentinelone
FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
blogs_sentinelone·2026-03-10
FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
## Overview
Throughout early 2026, SentinelOne’s® Digital Forensics & Incident Response (DFIR) team has responded to several incidents where FortiGate Next-Generation Firewall (NGFW) appliances have been compromised to establish a foothold into the targeted environment. Each incident was detected and stopped during the lateral movement phase of the attack.
Fortinet has disclosed and issued patches for several high-severity vulnerabilities allowing unauthorized access during the activity period of our investigations. Successful exploitation of these flaws allows an attacker to extract the configuration file from the FortiGate appliance, which frequently contains service account credentials and valuable network topology information for the targeted environment.
We observed a consistent th
Checkpoint
2nd February – Threat Intelligence Report
blogs_checkpoint·2026-02-02
CVE-2025-8088 2nd February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 2nd February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 2nd February, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
MicroWorld Technologies, maker of eScan antivirus, has suffered a supply-chain compromise. Malicious updates were pushed via the legitimate eScan updater, delivering multi-stage malware that establishes persistence, enables remote access, and blocks automatic updates. In response, eScan shut down its global update service
Bleepingcomputer
Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
blogs_bleepingcomputer·2026-01-27·CVSS 9.8
CVE-2026-24858 [CRITICAL] Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
## Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
## Lawrence Abrams
Fortinet has confirmed a new, actively exploited critical FortiCloud single sign-on (SSO) authentication bypass vulnerability, tracked as CVE-2026-24858, and says it has mitigated the zero-day attacks by blocking FortiCloud SSO connections from devices running vulnerable firmware versions.
The flaw allows attackers to abuse FortiCloud SSO to gain administrative access to FortiOS, FortiManager, and FortiAnalyzer devices registered to other customers, even when those devices were fully patched against a previously disclosed vulnerability.
The confirmation comes after Fortinet customers reported compromised FortiGate firewalls on January 21, with attackers creating new local administrator accounts
Wiz
CVE-2026-24858 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.7
CVE-2026-24858 [MEDIUM] CVE-2026-24858 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24858 :
FortiOS vulnerability analysis and mitigation
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 ma
Recorded Future
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
blogs_recorded_future·CVSS 4.9
[MEDIUM] January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
# January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
January 2026 saw a modest 5% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 23 vulnerabilities requiring immediate remediation, up from 22 in December 2025. Noteworthy trends last month included Russian state-sponsored exploitation of a Microsoft Office zero-day and critical authentication bypass flaws affecting enterprise infrastructure.
What security teams need to know:
- APT28's Operation Neusploit: Russian state-sponsored actors exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files, delivering MiniDoor, PixyNetLoader, and Covenant Grunt implants
- Microsoft and SmarterTools lead concerns: These vendors accounte
2026-01-27
Published
2026-01-27
Added to CISA KEV
Exploited in the wild