Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Hackers Bypass FortiCloud SSO, Target Fortinet Security Products
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Hackers Bypass FortiCloud SSO, Target Fortinet Security Products

Highlights

  • Threat actors exploited a FortiCloud SSO flaw to bypass authentication controls.

  • Fortinet issued mitigations but has not yet released comprehensive patches.

  • Experts advise strict access controls and close monitoring of firewall devices.

Samantha Reed
Last updated: 29 January, 2026 - 1:50 am 1:50 am
Samantha Reed 1 hour ago
Share
SHARE

Contents
How Did Attackers Exploit the FortiCloud SSO Flaw?What Steps Are Being Taken to Address the Vulnerability?How Are Customers and Industry Experts Reacting?

A newly disclosed vulnerability is challenging the security of Fortinet’s popular firewall and management products, exposing customers to unauthorized access through FortiCloud’s single sign-on (SSO) mechanism. This incident, which allowed attackers to use compromised FortiCloud accounts to alter device configurations and access sensitive systems, has heightened concerns among cybersecurity professionals. Organizations across various sectors are now assessing their risk, given the widespread use of FortiAnalyzer, FortiManager, FortiOS, FortiProxy, and FortiWeb. The issue emerges during an ongoing period of vulnerability fatigue among Fortinet customers, as repeated defects continue to place organizations’ security posture under pressure.

While Fortinet has addressed multiple zero-day vulnerabilities in the past, earlier disclosures have typically been followed by prompt patches and more detailed incident explanations. However, with CVE-2026-24858, uncertainty remains regarding whether the issue circumvents previous fixes or introduces a new attack vector. In contrast to the vendor’s previous practices, the delay in delivering patches for this flaw and ambiguity about its connection to December’s similar vulnerabilities have stirred broader unease among customers and industry experts. Recent findings indicate almost 10,000 affected devices remain exposed, especially in the United States, underscoring the persistent challenge companies face in staying secure as attackers probe for unpatched systems.

How Did Attackers Exploit the FortiCloud SSO Flaw?

Attackers gained illicit access by leveraging weaknesses in the FortiCloud SSO flow, allowing them to log into devices registered to accounts other than their own. These exploits, traced to malicious FortiCloud accounts that Fortinet has since blocked, resulted in rogue firewall reconfigurations, creation of new unauthorized users, and changes to VPN settings. Fortinet responded by temporarily disabling the SSO service before restoring it with added restrictions designed to block logins from vulnerable device versions. The company has not confirmed a timeline for the release of comprehensive patches.

What Steps Are Being Taken to Address the Vulnerability?

Fortinet issued a security advisory with recommendations for mitigation, and external researchers such as Arctic Wolf reported a pause in observed exploitation after these actions. The Cybersecurity and Infrastructure Security Agency (CISA) swiftly added the flaw to its catalog of known exploited vulnerabilities and distributed Fortinet’s guidance across government and private networks. Researchers are still working to measure the full impact, but industry partners urge vigilance and adherence to best security practices.

“There are those that know they’re affected, and likely a number that are unaware,”

said Ben Harris of watchTowr, reflecting on the uncertainty surrounding the incident’s scope.

How Are Customers and Industry Experts Reacting?

Frustration has mounted among organizations relying on Fortinet products, many of whom note an increasing frequency of critical vulnerabilities. Joe Toomey, an executive with Coalition, highlighted the recurrence of zero-days in Fortinet solutions and expressed doubts over the vendor’s commitment to effective security.

“All of which makes one begin to wonder if Fortinet is really taking security seriously,”

Toomey stated, echoing sentiments felt within portions of the cybersecurity community. Despite some praise for Fortinet’s clear communication and rapid containment measures, extended wait times for fixes and the high number of advisories continue to shape customers’ perceptions.

Analysis of recent incidents and community feedback reveals a need for ongoing vigilance when deploying network hardware solutions such as those marketed under the Fortinet brand. As attackers increasingly focus on exploiting hardware authentication flows, organizations are encouraged to regularly audit exposed management interfaces, restrict external access, and apply all vendor-suggested mitigations. The consistently high number of Fortinet vulnerabilities reported in global tracking databases highlights the necessity for more robust code review and vulnerability management processes across the industry. For security teams, proactive visibility and layered controls remain essential, especially as attackers adapt to patch cycles and disclosure timelines.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

Cybercriminals and State Groups Target WinRAR Vulnerability, Google Confirms

Experts Question CISA’s Quantum-Resistant Tech Guidance for Agencies

Cybercriminals Use Voice-Phishing to Breach SSO Accounts and Demand Ransom

Researchers Warn ChatGPT Extensions Steal User Data and Credentials

NIST Faces Staff Cuts While Accelerating Encryption Validation Efforts

Share This Article
Facebook Twitter Copy Link Print
Samantha Reed
By Samantha Reed
Samantha Reed is a 40-year-old, New York-based technology and popular science editor with a degree in journalism. After beginning her career at various media outlets, her passion and area of expertise led her to a significant position at Newslinker. Specializing in tracking the latest developments in the world of technology and science, Samantha excels at presenting complex subjects in a clear and understandable manner to her readers. Through her work at Newslinker, she enlightens a knowledge-thirsty audience, highlighting the role of technology and science in our lives.
Previous Article Tesla Ends Model S and X, Focuses on Robotaxi and Optimus Growth
Next Article Tesla Ends Model S and Model X Production, Shifts to Optimus Robot

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Tesla Ends Model S and Model X Production, Shifts to Optimus Robot
Electric Vehicle
Tesla Ends Model S and X, Focuses on Robotaxi and Optimus Growth
Electric Vehicle
Analysts Project Only a Few Companies Will Deploy Humanoid Robots by 2028
Robotics
Tesla Invests $2 Billion in xAI to Advance AI Goals
Electric Vehicle
Tesla Reports Q4 2025 Earnings and Details xAI Investment
Electric Vehicle
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?