Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»CISA, security researchers warn FortiCloud SSO flaw is under attack
    Cybersecurity

    CISA, security researchers warn FortiCloud SSO flaw is under attack

    adminBy adminJanuary 29, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    CISA, security researchers warn FortiCloud SSO flaw is under attack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Federal authorities and security researchers are warning about a critical vulnerability in Fortinet FortiCloud single sign-on, which is currently under exploitation. 

    The flaw, tracked as CVE-2026-24858, allows an attacker with a registered device and a FortiCloud account to access devices registered to other accounts. FortiCloud SSO authentication needs to be enabled in those other devices in order for the attack to work. 

    The Cybersecurity and Infrastructure Security Agency on Wednesday warned that Fortinet has confirmed several forms of malicious activity, including hackers changing firewall configurations on FortiGate devices, creating false unauthorized accounts and making changes on VPN accounts in order to get access to new accounts.

    CISA said users who previously patched prior SSO bypass flaws in December, tracked as CVE-2025-59718 and CVE-2025-59719, were not protected from this vulnerability and needed to upgrade. CISA added the new flaw to its Known Exploited Vulnerabilities catalog. 

    Shadowserver reported about 10,000 vulnerable instances. 

    Fortinet released guidance on Tuesday for users to upgrade to a secure version. The flaw impacts users of multiple products.

    Fortinet on Monday disabled FortiCloud SSO in order to prevent abuse and restored access on Tuesday, according to a blog post. The company noted that access for vulnerable devices will no longer be supported.

    Researchers at Arctic Wolf began seeing a pattern of automated configuration changes to firewalls on Jan. 15. Hackers were creating generic accounts in order to gain persistence, making changes to allow VPN access to the accounts. This led to additional configuration changes and data exfiltration. 

    “Despite differing underlying technical flaws, there are still similarities between the December and January campaigns,” Arctic Wolf researchers told Cybersecurity Dive in an emailed statement. “In both cases, we observed successful authentication via Fortinet SSO followed by near-immediate download of firewall configuration files, often within seconds, suggesting automated or scripted behavior.”

    Attack CISA Flaw FortiCloud researchers Security SSO warn
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleEFF to Close Friday in Solidarity with National Shutdown
    Next Article Cisco adds intelligent policy enforcement to mesh firewall family
    admin
    • Website

    Related Posts

    Cisco brings agentic ops platform and security overhaul to Cisco Live

    June 2, 2026

    Attackers exploit Palo Alto GlobalProtect flaw days after disclosure

    June 2, 2026

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Boost Mobile Review – No-Contract 5G Plans Starting at $25/Month

    June 4, 2026

    Google Confirms LLMs.txt Has No Current Implementation

    June 4, 2026

    Will Broadcom’s VMware strategy keep paying big dividends?

    June 4, 2026

    How Google Display exclusions guide AI-driven optimization

    June 4, 2026
    Categories
    • Blogging (89)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (235)
    • SEO & Digital Marketing (1,365)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (331)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Boost Mobile Review – No-Contract 5G Plans Starting at $25/Month

    June 4, 2026

    Google Confirms LLMs.txt Has No Current Implementation

    June 4, 2026

    Will Broadcom’s VMware strategy keep paying big dividends?

    June 4, 2026
    Most Popular
    • Boost Mobile Review – No-Contract 5G Plans Starting at $25/Month
    • Google Confirms LLMs.txt Has No Current Implementation
    • Will Broadcom’s VMware strategy keep paying big dividends?
    • How Google Display exclusions guide AI-driven optimization
    • How to show in search, social, and AI
    • 9 Best Cheap Cell Phone Plans That Will Save You Money
    • How To Fix Google Ads Smart Bidding With A Primary vs. Secondary Conversion Framework
    • What is Cisco Cloud Control and why should customers care?
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.