CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-01-27. EPSS: 85.8% chance of exploitation in the next 30 days.
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Affected products
- Fortinet Fortianalyzer: from 7.0.0, up to and including 7.0.15; from 7.2.0, up to and including 7.2.11; from 7.4.0, before 7.4.10 (fixed in 7.4.10); from 7.6.0, before 7.6.6 (fixed in 7.6.6)
- Fortinet FortiManager: from 7.0.0, up to and including 7.0.15; from 7.2.0, up to and including 7.2.11; from 7.4.0, before 7.4.10 (fixed in 7.4.10); from 7.6.0, before 7.6.6 (fixed in 7.6.6)
- Fortinet Fortinac-F: from 7.6.3, before 7.6.6 (fixed in 7.6.6)
- Fortinet FortiOS: from 7.0.0, up to and including 7.0.18; from 7.2.0, up to and including 7.2.12; from 7.4.0, before 7.4.11 (fixed in 7.4.11); from 7.6.0, before 7.6.6 (fixed in 7.6.6)
- Fortinet FortiProxy: from 7.0.0, up to and including 7.0.22; from 7.2.0, up to and including 7.2.15; from 7.4.0, up to and including 7.4.12; from 7.6.0, up to and including 7.6.4
- Fortinet FortiWeb: from 7.4.0, up to and including 7.4.11; from 7.6.0, up to and including 7.6.6; from 8.0.0, up to and including 8.0.3
- Siemens Ruggedcom APE1808 Firmware: affected versions not specified
Published 2026-01-27. Last modified 2026-06-17.