Fortinet has disclosed a critical authentication bypass vulnerability, tracked as CVE-2026-24858, that is being actively exploited in the wild. The flaw affects Fortinet products using FortiCloud Single Sign-On (SSO), including FortiOS, FortiManager, and FortiAnalyzer. Successful exploitation allows unauthenticated or low-privileged attackers to gain unauthorized administrative access to affected devices, posing a significant risk to enterprise network security environments worldwide. The vulnerability stems from a logic flaw in FortiCloud SSO’s authentication handling, classified as an authentication bypass using an alternate path or channel. An attacker with a valid FortiCloud account and a registered device can abuse this weakness to authenticate to other users’ Fortinet devices when FortiCloud SSO is enabled. Although SSO is not enabled by default on factory-fresh devices, it may be automatically activated during FortiCare registration unless explicitly disabled. Threat actors have been observed leveraging this flaw to log in via malicious FortiCloud accounts and subsequently create local administrator users for persistence. The impact of CVE-2026-24858 is severe, enabling full administrative compromise of network security appliances and potential exposure of sensitive firewall configurations. Fortinet confirmed active exploitation and temporarily disabled FortiCloud SSO server-side to mitigate risk until customers apply patches. Organizations using affected Fortinet products are strongly advised to upgrade to fixed firmware versions immediately, disable FortiCloud SSO if not required, audit authentication logs for suspicious activity, and restrict administrative access to trusted networks to reduce exposure.
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...
A large-scale Android malware campaign known as NoVoice was discovered on Google Play, where over 50 seemingly legitimate applications were used to distribute malicious code. These...
A recent cyber campaign has been observed targeting procurement and sales professionals through RFQ (Request for Quotation) themed phishing emails. Attackers impersonate legitimate...