CVE-2026-24858 KEV
Patch first
On CISA KEV — known exploited in the wild, due 2026-01-30.
Description
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 85.8% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-288 |
| On CISA KEV | yes — remediate by 2026-01-30 |
| Public exploit | none known |
| Published | 2026-01-27 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability |
|---|---|
| Added | 2026-01-27 |
| Due | 2026-01-30 |
| Vendor / product | Fortinet / Multiple Products |
| Ransomware use | none reported |
Affected (8)
| Vendor | Product |
|---|---|
| fortinet | fortianalyzer |
| fortinet | fortimanager |
| fortinet | fortinac-f |
| fortinet | fortios |
| fortinet | fortiproxy |
| fortinet | fortiweb |
| siemens | ruggedcom ape1808 |
| siemens | ruggedcom ape1808 firmware |
References
→ the Explorer · watch your stack · NVD