Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected
In order to fix a serious vulnerability affecting FortiOS that has been actively exploited in the wild, Fortinet has started to release security patches.
The vulnerability has been identified as a FortiOS single sign-on (SSO) authentication bypass and has been given the CVE identification CVE-2026-24858 (CVSS score: 9.4). FortiManager and FortiAnalyzer are also impacted by the bug. The company stated that it is still looking into whether the issue affects other products, such as FortiWeb and FortiSwitch Manager.
According to a Fortinet advisory issued on Tuesday, an attacker with a FortiCloud account and a registered device may be able to log into other devices registered to other accounts if FortiCloud SSO authentication is enabled on those devices due to an Authentication Bypass U...

