Fortinet has disclosed a critical authentication bypass vulnerability, tracked as CVE-2026-24858, that is being actively exploited in the wild. The flaw affects Fortinet products using FortiCloud Single Sign-On (SSO), including FortiOS, FortiManager, and FortiAnalyzer. Successful exploitation allows unauthenticated or low-privileged attackers to gain unauthorized administrative access to affected devices, posing a significant risk to enterprise network security environments worldwide. The vulnerability stems from a logic flaw in FortiCloud SSO’s authentication handling, classified as an authentication bypass using an alternate path or channel. An attacker with a valid FortiCloud account and a registered device can abuse this weakness to authenticate to other users’ Fortinet devices when FortiCloud SSO is enabled. Although SSO is not enabled by default on factory-fresh devices, it may be automatically activated during FortiCare registration unless explicitly disabled. Threat actors have been observed leveraging this flaw to log in via malicious FortiCloud accounts and subsequently create local administrator users for persistence. The impact of CVE-2026-24858 is severe, enabling full administrative compromise of network security appliances and potential exposure of sensitive firewall configurations. Fortinet confirmed active exploitation and temporarily disabled FortiCloud SSO server-side to mitigate risk until customers apply patches. Organizations using affected Fortinet products are strongly advised to upgrade to fixed firmware versions immediately, disable FortiCloud SSO if not required, audit authentication logs for suspicious activity, and restrict administrative access to trusted networks to reduce exposure.
A critical security issue in the Marimo Python notebook environment has raised serious alarm in the cybersecurity community due to its ability to enable unauthenticated remote comm...
A sophisticated software supply chain attack targeted the widely used Nx Console extension on the Microsoft Visual Studio Code Marketplace, potentially exposing more than two milli...
Critical security flaws have been discovered in the workflow automation platform n8n, prompting urgent warnings from cybersecurity researchers. The vulnerabilities, tracked as CVE-...