Fortinet has confirmed a new, actively exploited critical FortiCloud single sign-on (SSO) authentication bypass vulnerability, tracked as CVE-2026-24858, and says it has mitigated the zero-day attacks by blocking FortiCloud SSO connections from devices running vulnerable firmware versions. The flaw allows attackers to abuse FortiCloud SSO to gain administrative access to FortiOS, FortiManager, and FortiAnalyzer devices registered to other customers, even when those devices were fully patched against a previously disclosed vulnerability. The confirmation comes after Fortinet customers reported compromised FortiGate firewalls on January 21, with attackers creating new local administrator accounts via FortiCloud SSO on devices running the latest available firmware. The attacks were initially thought to be through a patch bypass for CVE-2025-59718, a previously exploited critical FortiCloud SSO authentication bypass flaw that was patched in December 2025. Fortinet admins reported that the hackers were logging into FortiGate devices via FortiCloud SSO using the email address cloud-init@mail.io, then creating new local admin accounts. Logs shared by impacted customers showed similar indicators observed during December exploitation. On January 22, cybersecurity firm Arctic Wolf confirmed the attacks, saying the attacks appeared automated, with new rogue admin and VPN-enabled accounts created and firewall configurations exfiltrated within seconds. Arctic Wolf said the attack appeare...
Fortinet blocks exploited FortiCloud SSO zero day until patch is ready
BleepingComputer
·Lawrence Abrams
·Published Jan 27, 2026
·Updated
Affected Software
3 affected components
Fortinet FortiOS<latest
Fortinet FortiManager<latest
Fortinet FortiAnalyzer<latest
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical zero-day vulnerability in FortiCloud's single sign-on system that is currently being exploited.
2
What security implications are discussed in the article?
The article highlights the risk of authentication bypass in FortiCloud, potentially allowing unauthorized access.
3
What products or software are affected by the vulnerability?
The vulnerability affects Fortinet's FortiOS, FortiManager, and FortiAnalyzer software.
4
What has Fortinet done in response to the vulnerability?
Fortinet has implemented measures to block the exploit until a patch is available.
5
What is the identifier for the vulnerability discussed in the article?
The vulnerability is tracked as CVE-2026-24858.