forticloud-sso-2026 · Disclosed 2026-01-22
FortiCloud SSO: abuse on fully patched devices
Fortinet disclosed FortiCloud SSO abuse affecting fully patched FortiOS and attacker-created administrator accounts.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
Unauthorized SSO logins affected fully patched devices on January 22; the issue concerns FortiCloud SSO, not all third-party SAML IdPs.
[s1]Update Jan 22 / Update Jan 28 - Reported fact
The Fortinet-submitted CVE-2026-24858 describes FortiCloud SSO authentication bypass.
[s2]Description / vendor references
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Fortinet reported disabling malicious cloud accounts, suspending SSO, and restricting connections to patched versions.
[s1]Updates Jan 22–30
Evidence relevant to prevention
Exploited before disclosure
Exploitation preceded disclosure. Inspect FortiCloud SSO use and administrator creation in addition to patching.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
Individual intrusion dates and impact are unknown; affected products and fixes require current vendor guidance.
Sources
[s1] Fortinet · Primary source
Analysis of SSO abuse on FortiOS ↗Published 2026-01-22 · Reviewed 2026-10-02
[s2] NIST / Fortinet · Primary source
CVE-2026-24858 ↗Reviewed 2026-10-02