In January 2026, a serious cybersecurity incident affected Fortinet products, a leading company in the production of cybersecurity devices. The discovery of a critical vulnerability forced the company to temporarily disable one of its main services to protect customers from potential cyber attacks.
The vulnerability, identified as CVE-2026-24858, affected several Fortinet products including FortiGate firewalls, FortiManager, and FortiAnalyzer. It is a flaw that allowed bypassing the FortiCloud SSO (Single Sign-On) authentication system, enabling attackers to access devices without valid credentials. Malicious activity was detected starting from January 20-21, 2026, when several customers reported security breaches. The attackers created local administrative accounts with names like “audit”, “backup”, “itadmin”, “secadmin”, “support”, and “system”, using these to extract potentially sensitive configuration files.
The severity of the vulnerability is highlighted by its CVSS score of 9.4 out of 10, indicating an extremely high risk. Fortinet devices are widely used by companies and government organizations to protect their networks, making this vulnerability particularly concerning. If successfully exploited, it could allow attackers to compromise entire corporate networks, access sensitive data, and potentially install malware.
In response to the incident, Fortinet took several decisive actions. On January 22, it blocked the identified malicious FortiCloud accounts (cloud-noc@mail.io and cloud-init@mail.io). On January 26, the company completely disabled the FortiCloud SSO service globally to prevent further attacks, reactivating it the following day with restrictions that prevent access to vulnerable devices. Fortinet also released security patches, such as FortiOS 7.4.11, with additional updates coming for other products. The vulnerability was added to CISA’s KEV (Known Exploited Vulnerabilities) catalog, the U.S. government cybersecurity agency.
- Fortinet customers should:
- Immediately update their devices to the latest available software version
- Verify the presence of suspicious administrative accounts created without authorization
- Check system logs to identify any anomalous activities
- Key points:
- A serious vulnerability in Fortinet products allowed attackers to bypass authentication and create unauthorized administrative accounts
- It is still unknown who is responsible for the attacks, or which specific organizations were affected beyond Fortinet customers
- The incident highlights the importance of regularly updating security devices and carefully monitoring network activities
Sources:
CSO Online, BleepingComputer, The Hacker News, SecurityWeek
Source: CSIRT Italia