FortiCloud SSO (FortiOS, FortiManager, FortiAnalyzer, FortiProxy)

CVE-2026-24858: Any FortiCloud account could log in to other customers' devices

With FortiCloud SSO login enabled, an attacker with their own FortiCloud account could log in as admin to devices belonging to other customers. Exploited on fully patched FortiGates in January 2026 to create admin accounts and steal configurations.

Published Updated

ExploitedYes, in CISA KEVAdded 27 Jan 2026
Ransomware useNot reportedPer CISA
SeverityCRITICALCVSS 3.1 9.4
EPSS86%Chance of exploitation in 30 days
Public exploitNot known
FixAvailable

Affected and fixed versions

Product / branchFixed in
FortiOS 7.6.0 to 7.6.5 / 7.4.0 to 7.4.107.6.6 / 7.4.11 or later
FortiOS 7.2.0 to 7.2.12 / 7.0.0 to 7.0.187.2.13 / 7.0.19 or later
FortiProxy 7.6.0 to 7.6.4 / 7.4.0 to 7.4.127.6.5 / 7.4.13 or later
FortiProxy 7.2.0 to 7.2.15 / 7.0.0 to 7.0.227.2.16 / 7.0.23 or later
FortiManager and FortiAnalyzer 7.6.0 to 7.6.5 / 7.4.0 to 7.4.97.6.6 / 7.4.10 or later
FortiManager and FortiAnalyzer 7.2.0 to 7.2.11 / 7.0.0 to 7.0.157.2.12 / 7.0.16 or later
FortiWeb 8.0.0 to 8.0.3 / 7.6.0 to 7.6.6 / 7.4.0 to 7.4.118.0.4 / 7.6.7 / 7.4.12 or later
FortiSwitchManager 7.2.0 to 7.2.8 / 7.0.0 to 7.0.77.2.9 / 7.0.8 or later
FortiNAC-F 7.6.3 to 7.6.57.6.6 or later
FortiOS 8.0 and 6.4, FortiGate Cloud, FortiManager Cloud, FortiAnalyzer CloudNot affected

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

FortiCloud SSO lets administrators log in to a FortiGate, FortiManager, FortiAnalyzer or FortiProxy with their FortiCloud account instead of a local password. On affected versions, the device didn’t properly check which FortiCloud account was logging in. Anyone with their own FortiCloud account and a registered device could log in as an administrator to devices registered to other customers.

Attackers used it to create local admin accounts for persistence and to download device configurations, which hold VPN settings, user accounts and secrets. It worked on FortiGates that were fully patched against the previous FortiCloud SSO bug, CVE-2025-59718, exploited six weeks earlier.

Fortinet shut the feature off on its side on 26 January 2026 and turned it back on a day later only for fixed versions. That stopped the attacks centrally, but any admin accounts and configuration copies the attackers already had stayed with them.

Am I affected?

Only devices with FortiCloud SSO admin login enabled. It’s off by default, but registering a device to FortiCare from its GUI turns it on unless you switch off Allow administrative login using FortiCloud SSO on the registration page. Many devices have it on without anyone deciding to.

Check:

  • FortiOS / FortiProxy: System > Settings > Allow administrative login using FortiCloud SSO, or get system global | grep forticloud.
  • FortiManager / FortiAnalyzer: System Settings > SAML SSO > Allow admins to login with FortiCloud.

Not affected: FortiOS 8.0 and 6.4, FortiGate Cloud, FortiManager Cloud and FortiAnalyzer Cloud, and setups that use your own identity provider (including FortiAuthenticator) instead of FortiCloud.

What to do

1. Upgrade to a fixed release (table above). Since Fortinet’s fix, FortiCloud SSO only works on fixed versions anyway.

2. Turn FortiCloud SSO login off unless you actively use it. The fewer cloud-reachable login paths, the better:

config system global
    set admin-forticloud-sso-login disable
end

On FortiManager and FortiAnalyzer:

config system saml
    set forticloud-sso disable
end

3. Check every device that had it enabled before 27 January 2026, whatever its version today:

  • Admin accounts you didn’t create. Names seen by Fortinet: audit, backup, itadmin, secadmin, support, backupadmin, deploy, remoteadmin, security, svcadmin, system. Attackers change names, so review the whole list.
  • SSO logins from the accounts and addresses below.
  • Configuration downloads you can’t explain.

4. If anything turns up, delete the rogue accounts and assume the configuration was stolen. Rotate local admin and VPN user passwords, LDAP and RADIUS secrets, and IPsec pre-shared keys.

Detection

  • Admin login events with the FortiCloud SSO method, especially from the email accounts listed below or from addresses that aren’t your admins’.
  • New administrator creation (configuration change logs for system admin) shortly after an SSO login.
  • Configuration backups or downloads in system event logs right after an SSO login.
  • In FortiManager and FortiAnalyzer, the same checks for SAML/FortiCloud logins and new admins.

Indicators of compromise

Most addresses belong to Cloudflare and are shared with legitimate users, so search logs for them rather than blocking them outright. Fortinet expects the attackers' accounts and addresses to change.

The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2026-24858.txt

IndicatorTypeReported by
cloud-noc@mail[.]ioEmailFortiCloud SSO login accountFortinet
cloud-init@mail[.]ioEmailFortiCloud SSO login accountFortinet
heltaylor.12@tutamail[.]comEmailFortiCloud SSO login accountFortinet
support@openmail[.]proEmailFortiCloud SSO login accountFortinet
104.28.244[.]114IPCloudflare addressFortinet
104.28.244[.]115IPCloudflare addressFortinet
104.28.244[.]116IPCloudflare addressFortinet
104.28.212[.]114IPCloudflare addressFortinet
104.28.212[.]115IPCloudflare addressFortinet
104.28.195[.]105IPCloudflare addressFortinet
104.28.195[.]106IPCloudflare addressFortinet
104.28.227[.]105IPCloudflare addressFortinet
104.28.227[.]106IPCloudflare addressFortinet
163.61.198[.]15IPFortinet
38.54.6[.]28IPFortinet
37.1.209[.]19IPThird party, via Fortinet
217.119.139[.]50IPThird party, via Fortinet

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.