Things aren't over yet for Fortinet customers – the security shop has disclosed yet another critical FortiCloud SSO vulnerability. Those hoping for a reprieve following last week's patch pantomime are out of luck. After users reported successful compromises of FortiCloud SSO accounts, despite being patched against an earlier flaw, the vendor confirmed there was an alternate attack path. According to a security advisory published Tuesday, that alternate path was assigned a separate vulnerability identifier (CVE-2026-24858, CVSS 9.4), and the company disabled FortiCloud SSO connections made from vulnerable versions. Patches are not yet ready. Fortinet confirmed that CVE-2026-24858, an authentication bypass bug, was exploited in the wild by two malicious FortiCloud accounts, but these were blocked as of January 22. Customers of FortiAnalyzer, FortiManager, FortiOS, and FortiProxy are all affected and should upgrade to the version recommended in the advisory to restore FortiCloud SSO services. Some versions have safe releases available already, although patches are still in the works for most. FortiWeb and FortiSwitch Manager are still being investigated for their exposure to the security flaws. The original attacks were first spotted by Arctic Wolf around January 15, and seemed to involve two bugs Fortinet patched in December, CVE-2025-59718 and CVE-2025-59719. The vulnerabilities in question allowed attackers to bypass SSO checks using specially crafted SAML responses, and the ...
Fortinet unearths another critical bug as SSO accounts borked post-patch
The Register
·Connor Jones
·Published Jan 28, 2026
·Updated
Affected Software
5 affected components
Fortinet FortiCloud<latest
Fortinet FortiAnalyzer<latest
Fortinet FortiManager<latest
Fortinet FortiOS<latest
Fortinet FortiProxy<latest
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a newly discovered critical vulnerability in FortiCloud affecting single sign-on (SSO) accounts.
2
What security implications are discussed in the article?
The article highlights that the vulnerability could lead to compromised SSO accounts, risking unauthorized access to Fortinet services.
3
What products or software are affected by this vulnerability?
The vulnerability affects Fortinet FortiCloud, FortiAnalyzer, FortiManager, FortiOS, and FortiProxy.
4
What steps should users take regarding this vulnerability?
Users are advised to monitor Fortinet's updates and apply patches promptly to mitigate potential risks.
5
Is there any mention of previous vulnerabilities in Fortinet products?
Yes, the article references a recent patch that did not fully resolve security issues for Fortinet customers.