Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026012901015454 | Publication Time | 2026/01/29 13:11 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/01/29 13:11 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】A Critical Security Vulnerability Has Been Identified in Fortinet FortiCloud SSO (CVE-2026-24858) |
|||
|
[Content] Fortinet has released a critical security advisory for FortiCloud SSO (CVE-2026-24858, CVSS: 9.8). This is an authentication bypass vulnerability that allows attackers who possess a FortiCloud account and registered devices to log in to other devices that are registered under different accounts. Note: Fortinet has currently observed active exploitation of this vulnerability. It is recommended to promptly implement temporary mitigation measures to prevent potential attacks targeting this vulnerability. |
|||
|
[Affected Platform] FortiAnalyzer versions 7.4.0 through 7.4.9 FortiAnalyzer versions 7.2.0 through 7.2.11 FortiAnalyzer versions 7.0.0 through 7.0.15 FortiManager versions 7.6.0 through 7.6.5 FortiManager versions 7.4.0 through 7.4.9 FortiManager versions 7.2.0 through 7.2.11 FortiManager versions 7.0.0 through 7.0.15 FortiOS versions 7.6.0 through 7.6.5 FortiOS versions 7.4.0 through 7.4.10 FortiOS versions 7.2.0 through 7.2.12 FortiOS versions 7.0.0 through 7.0.18 FortiProxy versions 7.6.0 through 7.6.4 FortiProxy versions 7.4.0 through 7.4.12 FortiProxy all versions of 7.2 FortiProxy all versions of 7.0 |
|||
|
[Recommended Actions] FortiAnalyzer version 7.4.10 or later FortiAnalyzer version 7.2.12 or later FortiAnalyzer version 7.0.16 or later FortiManager version 7.6.6 or later FortiManager version 7.4.10 or later FortiManager version 7.2.13 or later FortiManager version 7.0.16 or later FortiOS version 7.6.6 or later FortiOS version 7.4.11 or later FortiOS version 7.2.13 or later FortiOS version 7.0.19 or later FortiProxy version 7.6.6 or later FortiProxy version 7.4.13 or later Note: FortiProxy versions 7.2 and 7.0 should be migrated to a fixed supported version. |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-169-10678-e5cd4-1.html |
|||