An urgent security advisory warning of an authentication bypass vulnerability in its FortiCloud Single Sign-On (SSO) feature, which has been actively exploited in the wild.
The flaw, tracked as CVE-2026-24858, affects multiple Fortinet products, including FortiOS, FortiManager, FortiAnalyzer, and FortiProxy.
Critical Authentication Bypass Vulnerability
The vulnerability stems from an authentication bypass using an alternate path or channel (CWE-288).
It allows attackers with a FortiCloud account and a registered device to gain unauthorized access to other devices registered under different accounts, provided FortiCloud SSO authentication is enabled on those target devices.
While FortiCloud SSO is not enabled by default in factory settings, it becomes active when administrators register their devices with FortiCare via the device’s graphical user interface.
Unless administrators specifically turn off the “Allow administrative login using FortiCloud SSO” toggle during registration, the SSO feature remains enabled, creating a potential attack vector.
Active Exploitation and Fortinet’s Response
Fortinet discovered the vulnerability was being actively exploited by two malicious FortiCloud accounts. The company responded swiftly by locking out the suspicious accounts on January 22, 2026.
To protect customers from further exploitation, Fortinet temporarily disabled FortiCloud SSO on the FortiCloud side on January 26, 2026. The service was restored on January 27, 2026, with enhanced security measures in place.
The re-enabled FortiCloud SSO no longer supports login attempts from devices running vulnerable versions, effectively forcing organizations to upgrade to patched versions to restore SSO functionality.
This vulnerability impacts multiple Fortinet product lines. FortiOS versions 7.0.0 through 7.0.18, 7.2.0 through 7.2.12, 7.4.0 through 7.4.10, and 7.6.0 through 7.6.5 are affected.
FortiManager and FortiAnalyzer face similar version impacts across their 7.0, 7.2, 7.4, and 7.6 branches. FortiProxy versions 7.0 through 7.6.4 are also vulnerable. Notably, FortiOS 8.0 and version 6.4 across all affected products are not impacted.
Fortinet has released patches for several versions, with upgrade paths available to FortiOS 7.4.11, FortiManager 7.4.10, and FortiAnalyzer 7.4.10. Additional patches for other affected versions are forthcoming.
The company advises customers to use their upgrade tool at docs.fortinet.com/upgrade-tool to follow the recommended upgrade path, as reported by Fortiguard.
The threat actors demonstrated sophisticated tactics during exploitation. Following successful SSO authentication, attackers created local administrator accounts with names designed to blend in with legitimate system accounts.
Observed account names include “audit,” “backup,” “itadmin,” “secadmin,” “support,” “deploy,” “remoteadmin,” and “svcadmin.”
The attackers’ primary objectives included downloading customer configuration files and establishing persistent access by creating administrative accounts.
The threat actors utilized multiple IP addresses and switched to Cloudflare-protected infrastructure to obscure their activities.
Indicators of Compromise
| IOC Type | Value | Description |
|---|---|---|
| Email Account | cloud-noc@mail.io | Malicious SSO login account |
| Email Account | cloud-init@mail.io | Malicious SSO login account |
| IP Address | 104.28.244.115 | Cloudflare-protected attacker IP |
| IP Address | 104.28.212.114 | Cloudflare-protected attacker IP |
| IP Address | 104.28.212.115 | Cloudflare-protected attacker IP |
| IP Address | 104.28.195.105 | Cloudflare-protected attacker IP |
| IP Address | 104.28.195.106 | Cloudflare-protected attacker IP |
| IP Address | 104.28.227.106 | Cloudflare-protected attacker IP |
| IP Address | 104.28.227.105 | Cloudflare-protected attacker IP |
| IP Address | 104.28.244.114 | Cloudflare-protected attacker IP |
| IP Address | 37.1.209.19 | Third-party observed attacker IP |
| IP Address | 217.119.139.50 | Third-party observed attacker IP |
Organizations should immediately review their Fortinet devices for unauthorized administrator accounts, check logs for connections from the listed IP addresses, and prioritize upgrading to patched versions.
Even though FortiCloud SSO has been secured server-side, administrators can manually turn off the feature in system settings or via CLI commands as an additional precaution.