Fortinet zero-day bypasses FortiCloud single sign-on authentication

THE BRIEF
CyberScoop reported that Fortinet customers are facing an actively exploited zero-day, CVE-2026-24858, that can bypass authentication in the FortiCloud single sign-on flow. According to the report and Fortinet’s security advisory, exploitation occurred in some instances earlier in January. The flaw can provide privileged access to multiple Fortinet firewall products and related services. At the time of the report, Fortinet had not released patches covering multiple product versions, including FortiAnalyzer, FortiManager, FortiOS, FortiProxy and FortiWeb. The report describes the issue as a critical vulnerability and places it in a broader pattern of recurring Fortinet product defects. It says Fortinet vulnerabilities have appeared 24 times in the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog since late 2021. The supplied report does not establish the full scope of exploitation, affected customers or any resulting impact. Organizations using the named products should consult Fortinet’s advisory and assess their exposure while awaiting applicable fixes.
WHY IT MATTERS
An authentication bypass in the FortiCloud single sign-on flow may allow privileged access across multiple Fortinet products and related services. The reported active exploitation makes the issue time-sensitive, while the absence of patches across several named product versions complicates remediation. Fortinet’s history in the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities catalog also gives defenders reason to treat the advisory as a priority. However, the supplied report does not establish how broadly the vulnerability was exploited or what effects followed.
WHO SHOULD CARE
Security and infrastructure teams responsible for FortiAnalyzer, FortiManager, FortiOS, FortiProxy, FortiWeb or FortiCloud authentication should review the advisory. Security leaders overseeing firewall exposure and identity controls should also track vendor remediation.
WHAT TO DO NOW
- Review Fortinet’s security advisory for CVE-2026-24858 and identify which deployed products and versions are covered.
- Inventory FortiAnalyzer, FortiManager, FortiOS, FortiProxy and FortiWeb deployments that use or connect to FortiCloud single sign-on.
- Review relevant FortiCloud authentication and administrative access records for unexpected activity during the period identified by the advisory.