Fortinet faces second authentication flaw in a fortnight
Fortinet systems are under threat due to another authentication-based flaw, with security experts warning edge devices are now a vulnerable attack surface for networks.
A single sign-on (SSO) vulnerability allows attackers with a FortiCloud login and a registered device to bypass authentication and log into devices registered to other accounts where FortiCloud SSO authentication is enabled on those devices.
Designated as CVE-2026-24858, the new vulnerability echoes one unearthed only last week when researchers at Arctic Wolf found intrusions involving malicious SSO logins on FortiGate appliances. Bad actors were able to similarly bypass the SSO login authentication via a crafted security assertion markup language (SAML) message.
Arctic Wolf's VP for digital forensics incident response, Kerri Shafer-Page, agreed on the notable similarities, telling SDxCentral, " they both use the SSO authentication path, with automated follow-up actions to create generic user accounts for persistence. Exfiltration of firewall configuration is also typical in both instances."
The VP added the campaigns demonstrate how edge devices such as firewalls and VPN gateways provide a compelling target for opportunistic exploitation by threat actors.
"This has been a steady trend we've observed over the past few years, and we expect it to continue for the foreseeable future,” Shafer-Page said.
Fortinet claimed the new vulnerability was found being exploited in the wild by two malicious FortiCloud accounts, before being locked out on January 22. The firm then disabled SSO on the FortiCloud side on Monday (January 26) before renabling it a day later to no longer support login from devices running vulnerable versions.
The firm advised customers to upgrade, where applicable, to the latest versions of FortiAnalyzer, FortiManager, FortiOS, FortiProxy, and FortiWeb.
Fortinet's SSO troubles come in the same month that more than 10,000 Fortinet firewalls were reported to be at risk from a legacy vulnerability affecting FortiGate SSL VPN.
The firewall vulnerability allows users to log in without being prompted for two-factor authentication (2FA) if they change the case of their username. Affecting FortiOS versions 6.4.0, 6.2.0 to 6.2.3, and 6.0.9, users were recommended at the time to upgrade to newer versions of the Fortinet operating system.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
