Fortinet’s CVE-2026-24858 highlights a critical architectural anti-pattern that every product security team should understand: authentication bypass through alternate paths in SSO implementations. This critical zero-day (CVSS 9.4) allowed attackers with any FortiCloud account to authenticate to other customers’ FortiOS, FortiManager, and FortiAnalyzer devices – even on fully patched systems that had addressed previous SSO bypasses (CVE-2025-59718, CVE-2025-59719).
The root cause maps to CWE-288 (Authentication Bypass Using an Alternate Path or Channel). Exploitation began January 15, 2026, with automated attacks creating privileged admin accounts within seconds. Arctic Wolf observed two malicious FortiCloud accounts systematically targeting devices with SSO enabled – downloading configurations and establishing persistence. Fortinet disabled FortiCloud SSO globally on January 26, then restored it January 27 with server-side controls that block vulnerable firmware versions from authenticating. This server-side mitigation is notable: clients don’t need to patch to stop exploitation, though patches are rolling out across FortiOS 7.6.6+, FortiManager 7.6.6+, and FortiAnalyzer 7.6.6+.
From a threat modeling perspective, this underscores why SAML-based authentication paths require dedicated threat modeling sessions focused on token validation, session binding, and cross-tenant isolation. The vulnerability demonstrates that patching one authentication bypass doesn’t eliminate architectural weaknesses in the authentication flow itself. Shadow IT and devices auto-registered to FortiCare with default SSO settings created massive attack surface – over 10,000 devices remain exposed according to Shadowserver scans. Product security teams should audit all SSO implementations for similar alternate authentication paths, ensure multi-factor authentication isn’t bypassable through federated identity flows, and verify that SaaS-managed authentication services enforce device-side security posture before granting access.
https://www.fortiguard.com/psirt/FG-IR-26-060
https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios