EXPOSURES › CVE-2026-24858
CVE-2026-24858
HIGH ⌖ ON CISA KEV · EXPLOITEDFortinet's multiple products suffered an authentication bypass allowing unauthorized access via FortiCloud SSO.
An attacker with a FortiCloud account could exploit an authentication bypass in Fortinet's FortiAnalyzer, FortiManager, FortiOS, and FortiProxy to access other devices, potentially leading to unauthorized data access or manipulation.
Shame score — High-severity vulnerability enabling unauthorized access through SSO, with no patch available at the time of discovery.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.