• News/
  • https://www.theregister.com/2026/01/28/fortinet_forticloud_vuln/

Fortinet unearths another critical bug as SSO accounts borked post-patch

The Register
·
Connor Jones
·
Published Jan 28, 2026
·
Updated

Things aren't over yet for Fortinet customers – the security shop has disclosed yet another critical FortiCloud SSO vulnerability. Those hoping for a reprieve following last week's patch pantomime are out of luck. After users reported successful compromises of FortiCloud SSO accounts, despite being patched against an earlier flaw, the vendor confirmed there was an alternate attack path. According to a security advisory published Tuesday, that alternate path was assigned a separate vulnerability identifier (CVE-2026-24858, CVSS 9.4), and the company disabled FortiCloud SSO connections made from vulnerable versions. Patches are not yet ready. Fortinet confirmed that CVE-2026-24858, an authentication bypass bug, was exploited in the wild by two malicious FortiCloud accounts, but these were blocked as of January 22. Customers of FortiAnalyzer, FortiManager, FortiOS, and FortiProxy are all affected and should upgrade to the version recommended in the advisory to restore FortiCloud SSO services. Some versions have safe releases available already, although patches are still in the works for most. FortiWeb and FortiSwitch Manager are still being investigated for their exposure to the security flaws. The original attacks were first spotted by Arctic Wolf around January 15, and seemed to involve two bugs Fortinet patched in December, CVE-2025-59718 and CVE-2025-59719. The vulnerabilities in question allowed attackers to bypass SSO checks using specially crafted SAML responses, and the ...

Read full article

Affected Software

5 affected components
Fortinet FortiCloud<latest
Fortinet FortiAnalyzer<latest
Fortinet FortiManager<latest
Fortinet FortiOS<latest
Fortinet FortiProxy<latest
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a newly discovered critical vulnerability in FortiCloud affecting single sign-on (SSO) accounts.

2

What security implications are discussed in the article?

The article highlights that the vulnerability could lead to compromised SSO accounts, risking unauthorized access to Fortinet services.

3

What products or software are affected by this vulnerability?

The vulnerability affects Fortinet FortiCloud, FortiAnalyzer, FortiManager, FortiOS, and FortiProxy.

4

What steps should users take regarding this vulnerability?

Users are advised to monitor Fortinet's updates and apply patches promptly to mitigate potential risks.

5

Is there any mention of previous vulnerabilities in Fortinet products?

Yes, the article references a recent patch that did not fully resolve security issues for Fortinet customers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203