News

Fortinet blocks exploited FortiCloud SSO zero day until patch is ready

  • Lawrence Abrams--BleepingComputer
  • published date: 2026-01-27 23:19:42 UTC

Fortinet has confirmed a new, actively exploited critical FortiCloud single sign-on (SSO) authentication bypass vulnerability, tracked as CVE-2026-24858, and says it has mitigated the zero-day attacks by blocking FortiCloud SSO connections from devices runnin…

Fortinet has confirmed a new, actively exploited critical FortiCloud single sign-on (SSO) authentication bypass vulnerability, tracked as CVE-2026-24858, and says it has mitigated the zero-day attack… [+5402 chars]