Cyber Security News

3,280,081 Fortinet Devices Online With Exposed Web Properties Under Risk

Over 3,280,081 Fortinet Devices Were exposed, with web properties running vulnerable Fortinet devices affected by CVE-2026-24858, a severe authentication-bypass flaw actively exploited in the wild.

The vulnerability, rated 9.4 on the CVSS scale, affects multiple Fortinet product lines, including FortiOS, FortiManager, FortiAnalyzer, FortiProxy, and FortiWeb.

Critical Authentication Bypass Exploited in Active Attacks

CVE-2026-24858 allows threat actors with a FortiCloud account and a registered device to authenticate into other organizations’ devices when FortiCloud SSO is enabled.

While this feature is disabled by default, administrators frequently enable it during FortiCare device registration unless they explicitly toggle off the “Allow administrative login using FortiCloud SSO” option.

CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on January 27, 2026, establishing a remediation deadline of January 30, 2026, the same day as this report.

FieldDescription
CVECVE-2026-24858 (CVSS 9.4)
IssueCritical auth bypass via FortiCloud SSO allowing cross-account device access
Affected ProductsFortiOS, FortiManager, FortiAnalyzer, FortiProxy, FortiWeb
Vulnerable VersionsMultiple versions across 7.x–8.x branches

Fortinet confirmed active exploitation on January 22, 2026, identifying two malicious FortiCloud accounts, cloud-noc@mail.io and cloud-init@mail.io, responsible for the attacks.

Threat actors leveraged the vulnerability to download device configurations and establish persistence.

By creating local administrator accounts with familiar names such as “audit,” “backup,” “itadmin,” “secadmin,” “support,” “svcadmin,” or “system.”

In response, Fortinet temporarily disabled FortiCloud SSO on January 26, 2026, and re-enabled it the following day with version-based restrictions blocking vulnerable devices from authentication.

The vulnerability affects a wide range of versions across Fortinet’s enterprise security portfolio.

FortiOS versions 7.6.0 through 7.6.5, 7.4.0 through 7.4.10, 7.2.0 through 7.2.12, and 7.0.0 through 7.0.18 require immediate patching.

FortiManager and FortiAnalyzer share similar vulnerable version ranges, while FortiProxy and FortiWeb face exposure across multiple major releases. FortiSwitch Manager remains under investigation.

Patches are currently available for select branches, with FortiOS requiring upgrades to version 7.4.11 or 7.6.6, FortiManager needing 7.4.10 or 7.6.6, and FortiAnalyzer requiring 7.2.12 or 7.0.16.

According to the Censys advisory, organizations that cannot patch immediately should disable FortiCloud SSO and review all admin accounts for unauthorized users matching attacker-created naming patterns.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.


Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago