A critical authentication bypass vulnerability, CVE-2026-24858, affects multiple Fortinet products (FortiOS, FortiManager, FortiAnalyzer and FortiProxy) when the FortiCloud single sign-on (SSO) login feature is enabled. The flaw is an Authentication Bypass that can allow an attacker who controls a FortiCloud account and a registered device to log into other devices registered to different accounts. Fortinet has reported active exploitation in the wild; observed malicious activity has included creation of local admin accounts, persistent configuration changes (including enabling VPN access), and exfiltration of device configuration data. Fortinet issued mitigations (including temporarily blocking FortiCloud SSO connections) and published PSIRT guidance and patches to address the issue.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

