LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 27, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 30, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-24858 to its Known Exploited Vulnerabilities catalog on Jan 27, 2026, with a federal patch deadline of Jan 30, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a…

This vulnerability affects Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy when FortiCloud SSO authentication is enabled. It permits an attacker who possesses a FortiCloud account and at least one registered device to authenticate to other devices that belong to different accounts. The issue therefore removes the account isolation that organizations normally expect from a shared cloud identity service.

How it works

The weakness is classified as CWE-288, authentication bypass using an alternate path or channel. When FortiCloud SSO is active, the product accepts authentication assertions from the FortiCloud service for any registered device.

Am I affected? How to find it in your systems

FortiAnalyzer, FortiManager, FortiOS, and FortiProxy are deployed as physical or virtual appliances that perform logging, management, firewall, and proxy functions. Inventory every instance of these products and determine whether FortiCloud SSO authentication is enabled on each one. Specific version numbers and configuration settings that trigger the issue must be confirmed against the vendor advisory.

How to remediate

Apply the vendor update referenced in the official advisory. After the update is installed, review all devices that previously used FortiCloud SSO and disable the feature unless it is explicitly required. Follow any additional configuration guidance supplied by the vendor for this class of authentication issue.

If you can't patch immediately

Disable FortiCloud SSO authentication on affected devices where operationally acceptable. Restrict network access to management interfaces so that only trusted administrative networks can reach them. Monitor authentication and session logs for unexpected FortiCloud-originated logins. Apply mitigations according to the vendor instructions and follow applicable BOD 22-01 guidance for cloud services.

If your data may have been exposed

Vulnerabilities that allow unauthorized access can result in data exposure or further compromise of the affected systems. Organizations can run a free exposure scan of their email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · Multiple Products
WeaknessCWE-288
Added to CISA KEVJan 27, 2026
Federal patch deadlineJan 30, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities