← Incident database

forticloud-sso-2026 · Disclosed 2026-01-22

FortiCloud SSO: abuse on fully patched devices

Fortinet disclosed FortiCloud SSO abuse affecting fully patched FortiOS and attacker-created administrator accounts.

Zero-dayImplementationCVE-2026-24858

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Unauthorized SSO logins affected fully patched devices on January 22; the issue concerns FortiCloud SSO, not all third-party SAML IdPs.

    [s1]Update Jan 22 / Update Jan 28
  • Reported fact

    The Fortinet-submitted CVE-2026-24858 describes FortiCloud SSO authentication bypass.

    [s2]Description / vendor references

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Fortinet reported disabling malicious cloud accounts, suspending SSO, and restricting connections to patched versions.

    [s1]Updates Jan 22–30

Evidence relevant to prevention

Exploited before disclosure

Exploitation preceded disclosure. Inspect FortiCloud SSO use and administrator creation in addition to patching.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

Individual intrusion dates and impact are unknown; affected products and fixes require current vendor guidance.

Sources

  1. [s1] Fortinet · Primary source

    Analysis of SSO abuse on FortiOS ↗

    Published 2026-01-22 · Reviewed 2026-10-02

  2. [s2] NIST / Fortinet · Primary source

    CVE-2026-24858 ↗

    Reviewed 2026-10-02