Fortinet has released patches for CVE-2026-24858, an authentication bypass exploited in the wild to compromise devices.
The flaw, tracked as CVE-2026-24858, allows an attacker with a registered device and a FortiCloud account to access devices ...
Fortinet released updates for an actively exploited FortiOS SSO authentication bypass flaw, CVE-2026-24858, now listed by CISA in KEV.
The Register on MSN
Fortinet unearths another critical bug as SSO accounts borked post-patch
More work for admins on the cards as they await a full dump of fixes Things aren't over yet for Fortinet customers – the ...
A recent Fortinet patch may not work as well as expected ...
Fortinet has confirmed a new, actively exploited critical FortiCloud single sign-on (SSO) authentication bypass vulnerability ...
Fortinet confirms active exploitation of a FortiCloud SSO authentication bypass affecting fully patched FortiGate devices via ...
CISA added the flaw to its KEVs catalog as Fortinet warned that patches for most affected versions remain “upcoming,” even though vulnerable devices can no longer use cloud SSO until upgraded.
To stop the ongoing attacks, the cybersecurity vendor took the drastic step of temporarily disabling FortiCloud single ...
Fortinet FortiGate devices are being targeted in automated attacks that create rogue accounts and steal firewall ...
CVE-2026-24858 affects dozens of Fortinet products and has already been added to CISA’s list of known exploited ...
Automated infections of potentially fully patched FortiGate devices are allowing threat actors to steal firewall ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results