Fortinet Blocks Exploited FortiCloud SSO Zero – Day Vulnerability
A recently discovered zero-day vulnerability in Fortinet's FortiCloud single sign-on (SSO) solution, tracked as CVE-2026-24858, has been actively exploited by attackers to gain administrative access to FortiOS, FortiManager, and FortiAnalyzer devices. This vulnerability, rated as critical with a CVSS score of 9.4, allows attackers to bypass authentication and access devices registered to other customers, even if those devices are fully patched against previously disclosed vulnerabilities. The flaw affects FortiCloud SSO, which is not enabled by default but can be automatically turned on when a device is registered with FortiCare. Fortinet has confirmed that the vulnerability has been exploited in the wild, with multiple customers reporting compromised FortiGate firewalls.
The attack vector involves exploiting an alternate authentication path in FortiCloud SSO, which remains vulnerable even on fully patched systems. Attackers can use this path to authenticate to other customers' devices, allowing them to create new local administrator accounts, download customer configuration files, and exfiltrate firewall configurations. The exploitation chain involves attackers logging into FortiGate devices via FortiCloud SSO using compromised email addresses, such as [email protected], and then creating new rogue admin accounts. Logs from impacted customers have shown similar indicators of compromise observed during previous exploitation attempts. Fortinet has taken steps to mitigate the attacks, including disabling FortiCloud SSO globally on the FortiCloud side and restricting access to devices running vulnerable firmware versions.
The exploitation of this vulnerability has significant strategic implications, as it allows attackers to gain unauthorized access to critical network devices, potentially leading to further lateral movement and compromise of sensitive data. Fortinet has advised customers to restrict administrative access to their devices and disable FortiCloud SSO as a mitigation until patches are released. Customers who detect indicators of compromise in their logs should treat their devices as fully compromised and take immediate action to restore configurations from known-clean backups and rotate all credentials. The fact that this vulnerability is actively being exploited in the wild, combined with its high CVSS score, makes it a critical threat that requires immediate attention from organizations using Fortinet products.
Attack Surface
Cloud Service
Tactics
Initial Access, Privilege Escalation, Lateral Movement
Techniques
- T1190 – Exploit Public-Facing Application
- T1078 – Valid Accounts
- T1098 – Account Manipulation
SuperPRO's Threat Countermeasures Procedures
- Disable FortiCloud SSO until patches are released
- Restrict administrative access to devices
- Monitor logs for indicators of compromise, such as new local administrator accounts or suspicious login activity
- Restore configurations from known-clean backups
- Rotate all credentials, including administrator passwords and API keys
- Upgrade to patched versions of FortiOS, FortiManager, and FortiAnalyzer once available
- Use a web application firewall (WAF) to detect and prevent exploitation attempts