FortiCloud SSO (FortiOS, FortiManager, FortiAnalyzer, FortiProxy)
CVE-2026-24858: Any FortiCloud account could log in to other customers' devices
With FortiCloud SSO login enabled, an attacker with their own FortiCloud account could log in as admin to devices belonging to other customers. Exploited on fully patched FortiGates in January 2026 to create admin accounts and steal configurations.
Published Updated
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| FortiOS 7.6.0 to 7.6.5 / 7.4.0 to 7.4.10 | 7.6.6 / 7.4.11 or later |
| FortiOS 7.2.0 to 7.2.12 / 7.0.0 to 7.0.18 | 7.2.13 / 7.0.19 or later |
| FortiProxy 7.6.0 to 7.6.4 / 7.4.0 to 7.4.12 | 7.6.5 / 7.4.13 or later |
| FortiProxy 7.2.0 to 7.2.15 / 7.0.0 to 7.0.22 | 7.2.16 / 7.0.23 or later |
| FortiManager and FortiAnalyzer 7.6.0 to 7.6.5 / 7.4.0 to 7.4.9 | 7.6.6 / 7.4.10 or later |
| FortiManager and FortiAnalyzer 7.2.0 to 7.2.11 / 7.0.0 to 7.0.15 | 7.2.12 / 7.0.16 or later |
| FortiWeb 8.0.0 to 8.0.3 / 7.6.0 to 7.6.6 / 7.4.0 to 7.4.11 | 8.0.4 / 7.6.7 / 7.4.12 or later |
| FortiSwitchManager 7.2.0 to 7.2.8 / 7.0.0 to 7.0.7 | 7.2.9 / 7.0.8 or later |
| FortiNAC-F 7.6.3 to 7.6.5 | 7.6.6 or later |
| FortiOS 8.0 and 6.4, FortiGate Cloud, FortiManager Cloud, FortiAnalyzer Cloud | Not affected |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
FortiCloud SSO lets administrators log in to a FortiGate, FortiManager, FortiAnalyzer or FortiProxy with their FortiCloud account instead of a local password. On affected versions, the device didn’t properly check which FortiCloud account was logging in. Anyone with their own FortiCloud account and a registered device could log in as an administrator to devices registered to other customers.
Attackers used it to create local admin accounts for persistence and to download device configurations, which hold VPN settings, user accounts and secrets. It worked on FortiGates that were fully patched against the previous FortiCloud SSO bug, CVE-2025-59718, exploited six weeks earlier.
Fortinet shut the feature off on its side on 26 January 2026 and turned it back on a day later only for fixed versions. That stopped the attacks centrally, but any admin accounts and configuration copies the attackers already had stayed with them.
Am I affected?
Only devices with FortiCloud SSO admin login enabled. It’s off by default, but registering a device to FortiCare from its GUI turns it on unless you switch off Allow administrative login using FortiCloud SSO on the registration page. Many devices have it on without anyone deciding to.
Check:
- FortiOS / FortiProxy: System > Settings > Allow administrative login using FortiCloud SSO, or
get system global | grep forticloud. - FortiManager / FortiAnalyzer: System Settings > SAML SSO > Allow admins to login with FortiCloud.
Not affected: FortiOS 8.0 and 6.4, FortiGate Cloud, FortiManager Cloud and FortiAnalyzer Cloud, and setups that use your own identity provider (including FortiAuthenticator) instead of FortiCloud.
What to do
1. Upgrade to a fixed release (table above). Since Fortinet’s fix, FortiCloud SSO only works on fixed versions anyway.
2. Turn FortiCloud SSO login off unless you actively use it. The fewer cloud-reachable login paths, the better:
config system global
set admin-forticloud-sso-login disable
end
On FortiManager and FortiAnalyzer:
config system saml
set forticloud-sso disable
end
3. Check every device that had it enabled before 27 January 2026, whatever its version today:
- Admin accounts you didn’t create. Names seen by Fortinet:
audit,backup,itadmin,secadmin,support,backupadmin,deploy,remoteadmin,security,svcadmin,system. Attackers change names, so review the whole list. - SSO logins from the accounts and addresses below.
- Configuration downloads you can’t explain.
4. If anything turns up, delete the rogue accounts and assume the configuration was stolen. Rotate local admin and VPN user passwords, LDAP and RADIUS secrets, and IPsec pre-shared keys.
Detection
- Admin login events with the FortiCloud SSO method, especially from the email accounts listed below or from addresses that aren’t your admins’.
- New administrator creation (configuration change logs for
system admin) shortly after an SSO login. - Configuration backups or downloads in system event logs right after an SSO login.
- In FortiManager and FortiAnalyzer, the same checks for SAML/FortiCloud logins and new admins.
Indicators of compromise
Most addresses belong to Cloudflare and are shared with legitimate users, so search logs for them rather than blocking them outright. Fortinet expects the attackers' accounts and addresses to change.
The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2026-24858.txt
| Indicator | Type | Reported by |
|---|---|---|
| cloud-noc@mail[.]io | EmailFortiCloud SSO login account | Fortinet |
| cloud-init@mail[.]io | EmailFortiCloud SSO login account | Fortinet |
| heltaylor.12@tutamail[.]com | EmailFortiCloud SSO login account | Fortinet |
| support@openmail[.]pro | EmailFortiCloud SSO login account | Fortinet |
| 104.28.244[.]114 | IPCloudflare address | Fortinet |
| 104.28.244[.]115 | IPCloudflare address | Fortinet |
| 104.28.244[.]116 | IPCloudflare address | Fortinet |
| 104.28.212[.]114 | IPCloudflare address | Fortinet |
| 104.28.212[.]115 | IPCloudflare address | Fortinet |
| 104.28.195[.]105 | IPCloudflare address | Fortinet |
| 104.28.195[.]106 | IPCloudflare address | Fortinet |
| 104.28.227[.]105 | IPCloudflare address | Fortinet |
| 104.28.227[.]106 | IPCloudflare address | Fortinet |
| 163.61.198[.]15 | IP | Fortinet |
| 38.54.6[.]28 | IP | Fortinet |
| 37.1.209[.]19 | IP | Third party, via Fortinet |
| 217.119.139[.]50 | IP | Third party, via Fortinet |
Sources
Page changelog
- Full analysis published.
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.