【Vulnerability Alert】A Critical Security Vulnerability Has Been Identified in Fortinet FortiCloud SSO (CVE-2026-24858)

publish date : 2026-01-30 update date : 2026-01-30

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026012901015454 Publication Time 2026/01/29 13:11
Incident Type ANA-Vulnerability Alert Discovery Time 2026/01/29 13:11
Impact Level Low  
[Subject]
【Vulnerability Alert】A Critical Security Vulnerability Has Been Identified in Fortinet FortiCloud SSO (CVE-2026-24858)

[Content]
Forwarded from TWCERTCC-200-202601-00000025

Fortinet has released a critical security advisory for FortiCloud SSO (CVE-2026-24858, CVSS: 9.8). This is an authentication bypass vulnerability that allows attackers who possess a FortiCloud account and registered devices to log in to other devices that are registered under different accounts.

Note: Fortinet has currently observed active exploitation of this vulnerability. It is recommended to promptly implement temporary mitigation measures to prevent potential attacks targeting this vulnerability.

(Information Sharing Level: WHITE (Information content can be publicly disclosed)

[Affected Platform]
FortiAnalyzer versions 7.6.0 through 7.6.5

FortiAnalyzer versions 7.4.0 through 7.4.9

FortiAnalyzer versions 7.2.0 through 7.2.11

FortiAnalyzer versions 7.0.0 through 7.0.15

FortiManager versions 7.6.0 through 7.6.5

FortiManager versions 7.4.0 through 7.4.9

FortiManager versions 7.2.0 through 7.2.11

FortiManager versions 7.0.0 through 7.0.15

FortiOS versions 7.6.0 through 7.6.5

FortiOS versions 7.4.0 through 7.4.10

FortiOS versions 7.2.0 through 7.2.12

FortiOS versions 7.0.0 through 7.0.18

FortiProxy versions 7.6.0 through 7.6.4

FortiProxy versions 7.4.0 through 7.4.12

FortiProxy all versions of 7.2

FortiProxy all versions of 7.0

[Recommended Actions]
FortiAnalyzer version 7.6.6 or later

FortiAnalyzer version 7.4.10 or later

FortiAnalyzer version 7.2.12 or later

FortiAnalyzer version 7.0.16 or later

FortiManager version 7.6.6 or later

FortiManager version 7.4.10 or later

FortiManager version 7.2.13 or later

FortiManager version 7.0.16 or later

FortiOS version 7.6.6 or later

FortiOS version 7.4.11 or later

FortiOS version 7.2.13 or later

FortiOS version 7.0.19 or later

FortiProxy version 7.6.6 or later

FortiProxy version 7.4.13 or later

Note: FortiProxy versions 7.2 and 7.0 should be migrated to a fixed supported version.

[Reference]
https://www.twcert.org.tw/tw/cp-169-10678-e5cd4-1.html
(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw