Security Advisory: Fortinet CVE-2026-24858 (Active Exploitation)

DataComm is monitoring CVE-2026-24858, an actively exploited authentication-bypass vulnerability tied to FortiCloud Single Sign-On (SSO) across multiple Fortinet products (including FortiOS, FortiManager, FortiAnalyzer, FortiProxy, and FortiWeb). CISA added this CVE to its Known Exploited Vulnerabilities (KEV) Catalog on January 27, 2026, underscoring the urgency to remediate. We recommend organizations apply Fortinet’s fixes immediately, confirm whether FortiCloud SSO administrative login is enabled in your environment, and review internet-exposed Fortinet devices for signs of compromise.
DataComm Networks Incorporated, a leader in Cybersecurity partner in the Tampa Bay Area and beyond.

Severity: Critical

Summary

Fortinet and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have confirmed active exploitation of a critical authentication bypass vulnerability, CVE-2026-24858, affecting multiple Fortinet products when FortiCloud Single Sign-On (SSO) is enabled. This vulnerability allows attackers to bypass authentication and gain unauthorized administrative access to affected devices.

Affected Products

  • FortiGate (FortiOS)
  • FortiManager
  • FortiAnalyzer
  • FortiProxy
  • FortiWeb

Vulnerability Overview

  • CVE ID: CVE-2026-24858
  • Type: Authentication bypass (CWE-288)
  • CVSS Score: 9.4 (Critical)
  • Condition: FortiCloud SSO enabled

Observed Activity

Reported exploitation activity includes unauthorized administrative access, creation of rogue admin accounts, and extraction of firewall and VPN configuration data.

Recommended Actions

  1. Apply Fortinet patches addressing CVE-2026-24858.
  2. Disable FortiCloud SSO if not required until systems are fully patched.
  3. Restrict administrative access to trusted networks only.
  4. Review logs and configurations for signs of unauthorized access.

Our Status

DataComm is actively monitoring this issue and validating patch levels in accordance with Fortinet and CISA guidance. Customers requiring assistance are encouraged to contact support.

Support

Email: support@www-prod.datacomm.com

Phone: (877) 544-3655

References

Latest posts

Technology Trends
Travis Norris

Update Fatigue: How the relentless pace of software updates is breaking user trust — and what organizations can do about it

Somewhere between the fourteenth update notification of the week and the third forced restart during a critical deadline, something breaks. Not the software — the user. They click “Remind me later.” Then again. And again. Eventually, they stop updating altogether.

This is update fatigue — and it’s quietly becoming one of the most significant and underappreciated vulnerabilities in organizational cybersecurity today.

Read More ⇾
Kofi's Korner - Insights from DataComm's Technical Solutions Team
Kofi's Korner
Kofi Kankam

Kofi’s Korner April 2026

Rising technology costs, evolving cyber threats, and increasingly complex IT environments are forcing organizations to rethink how they plan, protect, and scale their infrastructure. In this edition of Kofi’s Korner, we explore what’s driving today’s unpredictable pricing landscape, how a layered security approach strengthens resilience, and why solutions like SecurShield IDS/IPS are critical in a firewall-first world. Discover practical insights and strategies to help your organization stay secure, compliant, and ahead of what’s next.

Read More ⇾

SecurNOC

Monitor your network devices and view their configuration changes.

SecurPortal

A live look at your events, security event charts and tickets.

Ticketing Portal

Login here to easily add and managed trouble tickets.

Remote Support

Let DataComm remotely access your computer to render aid.