Thoughts on Fortinet’s CVE-2026-24858

Fortinet’s CVE-2026-24858 highlights a critical architectural anti-pattern that every product security team should understand: authentication bypass through alternate paths in SSO implementations. This critical zero-day (CVSS 9.4) allowed attackers with any FortiCloud account to authenticate to other customers’ FortiOS, FortiManager, and FortiAnalyzer devices – even on fully patched systems that had addressed previous SSO bypasses … Read more