An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] in FortiOS, FortiManager, FortiAnalyzer, FortiProxy, FortiSwitchManager, FortiWeb may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices. Please note that the FortiCloud SSO login feature is not enabled in default factory settings. However, when an administrator registers the device to FortiCare from the device's GUI, unless the administrator disables the toggle switch "Allow administrative login using FortiCloud SSO" in the registration page, FortiCloud SSO login is enabled upon registration. This vulnerability was found being exploited in the wild by two malicious FortiCloud accounts, which were locked out on 2026-01-22. In order to protect its customers from further exploit, Fortinet disabled FortiCloud SSO on FortiCloud side on 2026-01-26. It was re-enabled on 2026-01-27 and no longer supports login from devices running vulnerable versions. Consequently, customers must upgrade to the latest versions listed below for the FortiCloud SSO authentication to function. FortiManager Cloud, FortiAnalyzer Cloud, FortiGate Cloud are NOT impacted. Setups with Custom IdP for SSO instead of FortiCloud are not impacted (including setups using FortiAuthenticator as the Custom IdP)
FortiCloud SSO authentication no longer supports login from devices running vulnerable versions.
Therefore disabling FortiCloud SSO login on client side is not necessary at the moment. For reference, it can be nonetheless be done via the following: On FortiOS and FortiProxy: go to System -> Settings -> Switch "Allow administrative login using FortiCloud SSO" to Off. Or type the following command in CLI command line:
On FortiManager and FortiAnalyzer: go to System Settings -> SAML SSO -> Switch "Allow admins to login with FortiCloud" to Off. Or type the following command in CLI command line:
The actor has been observed to have logged in with the following user accounts.
[email protected] [email protected] [email protected] [email protected]
We expect these addresses may change in the future as action has been taken to neutralize these accounts.
The actor has been observed to log in via multiple IP addresses and appears to have switched to use Cloudflare protected IPs.
104.28.244.115 104.28.212.114 104.28.212.115 104.28.195.105 104.28.195.106 104.28.227.106 104.28.227.105 104.28.244.114 163.61.198.15 104.28.195.106 104.28.244.116 38.54.6.28
Additional IPs observed by a third party, not Fortinet:
37[.]1.209.19 217[.]119.139.50
Following authentication via SSO, it has been observed that the actor creates a local admin account with one of the following names. This has changed through our analysis, so Fortinet recommends reviewing all admin accounts to look for any unexpected entries.
audit backup itadmin secadmin support backupadmin deploy remoteadmin security svcadmin system adccount
2026-01-27: Initial publication
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
