peter bassill · operator
$ cve CVE-2026-24858 JSON

CVE-2026-24858 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 85.8% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-01-30.

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS85.8% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-288
On CISA KEVyes — remediate by 2026-01-30
Public exploitnone known
Published2026-01-27
Last modified2026-06-17

CISA KEV

NameFortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Added2026-01-27
Due2026-01-30
Vendor / productFortinet / Multiple Products
Ransomware usenone reported

Affected (8)

VendorProduct
fortinetfortianalyzer
fortinetfortimanager
fortinetfortinac-f
fortinetfortios
fortinetfortiproxy
fortinetfortiweb
siemensruggedcom ape1808
siemensruggedcom ape1808 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD