CVE-2026-24858 - Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
- Severity
- critical
- Product
- Fortinet Multiple Products
- Published
- 2026-01-27
- EPSS
- 0.858
- CISA KEV
- Known exploited
- Ransomware
- Known campaign use
References and validation
- https://github.com/search?q=CVE-2026-24858&type=repositories
- https://nvd.nist.gov/vuln/detail/CVE-2026-24858
Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.