CVE-2026-24858Active Exploitation(fortinet / fortianalyzer)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 141 mentions and remains active

Immediate actions

  • Patch fortinet fortianalyzer systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiNAC-F 7.6.3 through 7.6.5, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

10.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-01-30. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-288

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortianalyzer
  • fortimanager
  • fortinac-f
  • fortios

Threat summary

  • Active exploitation appears in 199 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 300 mentions across 42 observed days

What's happening

  • Active exploitation reported across 199 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 176 signals
  • Technical details provided in 173 signals
  • General: 37 classified signals
  • Peaked 40d ago at 141 mentions (2026-01-28); latest day: 1
  • 300 total mentions across 42 days

Affected systems

Products
fortianalyzerfortimanagerfortinac-ffortiosfortiproxyfortiwebruggedcom_ape1808ruggedcom_ape1808_firmware

1 version affected across 8 products

Deep dive

Activity timeline300 mentions / 42d
03571106141Mentions · 2026-01-27: 11Mentions · 2026-01-28: 141Mentions · 2026-01-29: 41Mentions · 2026-01-30: 17Mentions · 2026-01-31: 11Mentions · 2026-02-01: 4Mentions · 2026-02-02: 11Mentions · 2026-02-03: 7Mentions · 2026-02-04: 4Mentions · 2026-02-05: 4Mentions · 2026-02-06: 2Mentions · 2026-02-07: 3Mentions · 2026-02-08: 2Mentions · 2026-02-09: 2Mentions · 2026-02-10: 4Mentions · 2026-02-13: 1Mentions · 2026-02-17: 1Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-02-25: 2Mentions · 2026-02-26: 1Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-13: 2Mentions · 2026-03-16: 2Mentions · 2026-03-17: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 1Mentions · 2026-04-11: 1Mentions · 2026-04-17: 1Mentions · 2026-04-20: 1Mentions · 2026-05-05: 1Mentions · 2026-05-08: 6Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-06-29: 1Mentions · 2026-07-17: 2Mentions · 2026-08-03: 1Mentions · 2026-09-01: 1Mentions · 2026-09-02: 1PoC Mentioned / Linked · 2026-01-29: 1PoC Mentioned / Linked · 2026-01-30: 1PoC Mentioned / Linked · 2026-01-31: 1PoC Mentioned / Linked · 2026-02-02: 1PoC Mentioned / Linked · 2026-02-08: 1Exploit Tool / Code · 2026-01-30: 2Exploit Tool / Code · 2026-02-02: 1Exploit Tool / Code · 2026-02-08: 1Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-01-27: 7Active Exploitation · 2026-01-28: 99Active Exploitation · 2026-01-29: 26Active Exploitation · 2026-01-30: 10Active Exploitation · 2026-01-31: 7Active Exploitation · 2026-02-01: 1Active Exploitation · 2026-02-02: 7Active Exploitation · 2026-02-03: 3Active Exploitation · 2026-02-04: 2Active Exploitation · 2026-02-05: 2Active Exploitation · 2026-02-06: 1Active Exploitation · 2026-02-07: 3Active Exploitation · 2026-02-10: 2Active Exploitation · 2026-02-13: 1Active Exploitation · 2026-02-19: 1Active Exploitation · 2026-02-25: 2Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-11: 1Active Exploitation · 2026-03-13: 2Active Exploitation · 2026-03-16: 2Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-04-20: 1Active Exploitation · 2026-05-05: 1Active Exploitation · 2026-05-08: 5Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-06-29: 1Active Exploitation · 2026-09-01: 1Active Exploitation · 2026-09-02: 1Patch / Workaround · 2026-01-27: 5Patch / Workaround · 2026-01-28: 97Patch / Workaround · 2026-01-29: 28Patch / Workaround · 2026-01-30: 8Patch / Workaround · 2026-01-31: 6Patch / Workaround · 2026-02-01: 3Patch / Workaround · 2026-02-02: 5Patch / Workaround · 2026-02-03: 4Patch / Workaround · 2026-02-04: 2Patch / Workaround · 2026-02-05: 2Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-07: 2Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-16: 2Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-29: 1Patch / Workaround · 2026-07-17: 1Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-09-02: 1Technical Details · 2026-01-27: 7Technical Details · 2026-01-28: 73Technical Details · 2026-01-29: 27Technical Details · 2026-01-30: 11Technical Details · 2026-01-31: 7Technical Details · 2026-02-01: 2Technical Details · 2026-02-02: 7Technical Details · 2026-02-03: 5Technical Details · 2026-02-04: 2Technical Details · 2026-02-05: 4Technical Details · 2026-02-06: 1Technical Details · 2026-02-07: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-10: 4Technical Details · 2026-02-13: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-25: 2Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-20: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-17: 1Technical Details · 2026-08-03: 1Technical Details · 2026-09-01: 1Technical Details · 2026-09-02: 101-2701-3102-0402-0802-1702-2603-1103-2004-2006-2409-0109-02
Signal classification6 categories
Active Exploitation
13344.3%
Patch
9732.3%
General
3712.3%
Disclosure
3110.3%
PoC
10.3%
Exploit
10.3%
Referenced assets187 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-2711
Active Exploitation6Disclosure2General2Patch1
2026-01-28141
Active Exploitation54Disclosure10General17Patch60
2026-01-2941
Active Exploitation18Disclosure4General7Patch12
2026-01-3017
Active Exploitation7Disclosure2General4Patch3PoC1
2026-01-3111
Active Exploitation5Disclosure2General2Patch2
2026-02-014
Active Exploitation1General1Patch2
2026-02-0211
Active Exploitation4Disclosure2Patch5
2026-02-037
Active Exploitation3Disclosure1General1Patch2
2026-02-044
Active Exploitation2General1Patch1
2026-02-054
Active Exploitation1Disclosure1Patch2
2026-02-062
Active Exploitation1Patch1
2026-02-073
Active Exploitation3
2026-02-082
Exploit1General1
2026-02-092
Disclosure1General1
2026-02-104
Active Exploitation1Disclosure2Patch1
2026-02-131
Active Exploitation1
2026-02-171
Patch1
2026-02-191
Active Exploitation1
2026-02-201
Disclosure1
2026-02-252
Active Exploitation2
2026-02-261
Patch1
2026-03-041
Active Exploitation1
2026-03-051
Active Exploitation1
2026-03-101
Active Exploitation1
2026-03-111
Active Exploitation1
2026-03-132
Active Exploitation2
2026-03-162
Active Exploitation2
2026-03-171
Active Exploitation1
2026-03-201
Active Exploitation1
2026-03-231
Active Exploitation1
2026-04-111
Active Exploitation1
2026-04-171
Active Exploitation1
2026-04-201
Active Exploitation1
2026-05-051
Active Exploitation1
2026-05-086
Active Exploitation5Disclosure1
2026-06-231
Disclosure1
2026-06-241
Active Exploitation1
2026-06-291
Active Exploitation1
2026-07-172
Disclosure1Patch1
2026-08-031
Patch1
2026-09-011
Active Exploitation1
2026-09-021
Patch1
Full discourse20 posts
  • Simo@SimoKohonen
    General

    Fortinet CVE-2026-24858.. is this even real life anymore? ”An attacker’s valid FortiCloud session, tied to their own device, gets accepted as legitimate for other users’ devices.” https://t.co/SGZEwxTfel

    Post summary

    The tweet questions the relevance of Fortinet CVE-2026-24858, noting that attackers can misuse a valid FortiCloud session on other devices, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    94258981.7K447446.0K
    2.8K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🚨Malicious cyber actors are actively exploiting Fortinet authentication bypass vulnerability CVE-2026-24858, impacting FortiOS, FortiManager, FortiWeb, FortiProxy, & FortiAnalyzer. Review our Alert, check for IOCs, & apply vendor updates. More info: https://go.dhs.gov/iRT https://t.co/RxObsEArRl

    Post summary

    Fortinet’s CVE‑2026‑24858, an authentication bypass flaw affecting multiple FortiOS products, is being actively exploited; users are urged to review alerts, check IOCs, and apply vendor updates.

    331641153811057.0K
    291.8K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability Severity: Critical CVSS: 9.8 Zero Day: Yes CVE Published: January 27th, 2026 Advisory: https://github.com/advisories/GHSA-2x38-48vp-w23x An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

    Post summary

    A critical authentication bypass vulnerability in various Fortinet products is disclosed, including affected versions, CVSS score, and detailed technical description, without any PoC, exploitation evidence, or patch information.

    8932342914146.6K
    165.8K followersView on X
  • Juan Carlos Ortiz 🛡️ Ciberseguridad para Empresas@CycuraMX
    Active Exploitation

    🛡️ Falla grave en Fortinet permite entrar a firewalls sin contraseña Fortinet confirmó la explotación activa de la vulnerabilidad CVE-2026-24858. Afecta equipos como: - FortiGate - FortiManager - FortiWeb - FortiProxy - FortiAnalyzer. El problema ocurre cuando está habilitado SSO de FortiCloud. SSO significa Single Sign-On. Permite iniciar sesión una sola vez para administrar varios dispositivos. Aquí, ese mecanismo puede ser abusado. Un atacante con una cuenta válida de FortiCloud y un dispositivo registrado puede acceder a equipos de otros clientes. Sin contraseña adicional. Ni autorización. Fortinet observó cambios no autorizados. Reglas de firewall modificadas. VPNs creadas para dar acceso a cuentas nuevas. El riesgo es: - Control total del perímetro. - Acceso a redes internas. - Interrupción del negocio. CISA ya incluyó esta falla en su lista de vulnerabilidades explotadas activamente. 💡 ¿Qué deben hacer? Revisar si FortiCloud SSO está habilitado. Aplicar parches y guías oficiales de Fortinet de inmediato. Auditar configuraciones y accesos recientes en firewalls.

    Post summary

    Fortinet reports that CVE-2026-24858 is actively exploited through FortiCloud SSO, enabling attackers to control firewalls without password and gain network access; immediate patching and configuration review are required.

    2442149558.7K
    7.5K followersView on X
  • Hunter@HunterMapping
    Active Exploitation

    🚨Alert🚨 CVE-2026-24858: An Authentication Bypass Using an Alternate Path or Channel vulnerability in Fortinet. 🧐Detail :https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios 📊 2.5M Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Fortinet%20FortiAnalyzer%22%7C%7Cproduct.name%3D%22FortiManager%22%7C%7Cproduct.name%3D%22FortiOS%22 👇Query HUNTER : http://product.name="Fortinet FortiAnalyzer"||http://product.name="FortiManager"||http://product.name="FortiOS" 📰Refer:https://fortiguard.fortinet.com/psirt/FG-IR-26-060 https://www.bleepingcomputer.com/news/security/fortinet-blocks-exploited-forticloud-sso-zero-day-until-patch-is-ready/ https://securityonline.info/under-attack-critical-fortinet-auth-bypass-cve-2026-24858-exploited-in-the-wild/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    Fortinet’s authentication bypass vulnerability (CVE‑2026‑24858) is actively being exploited in the wild according to cited reports, though the notice does not provide a PoC, exploit code, or patch information.

    123901255012.8K
    25.4K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Fortinet authentication bypass vulnerability CVE-2026-24858, affecting multiple Fortinet products, to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/RX2pIirpK8

    Post summary

    Fortinet authentication bypass CVE-2026-24858 is listed as a known exploited vulnerability, and the tweet urges applying mitigations to protect organizations.

    5290941611.1K
    291.8K followersView on X
  • BleepingComputer@BleepinComputer
    Active Exploitation

    Fortinet has confirmed an actively exploited critical FortiCloud SSO auth bypass zero-day, tracked as CVE-2026-24858. Flaw exploited to: 🚨Create rogue admin, VPN accounts 🚨Steal firewall configs Patches are not available but mitigations in place. ➡️https://www.bleepingcomputer.com/news/security/fortinet-blocks-exploited-forticloud-sso-zero-day-until-patch-is-ready/

    Post summary

    CVE-2026-24858 is an actively exploited FortiCloud SSO authentication bypass that enables rogue admin and VPN accounts and theft of firewall configurations. No patch is yet available, only mitigations have been deployed.

    626286188.0K
    248.2K followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 Fortinet Confirms FortiCloud SSO Flaw Actively Exploited in the Wild Source: https://cybersecuritynews.com/fortinet-forticloud-sso-vulnerability/ 📌 Fortinet has confirmed a critical authentication bypass vulnerability in its FortiCloud SSO feature, actively exploited in the wild under CVE-2026-24858. 📌According to an advisory published on January 27, 2026, the flaw affects FortiOS, FortiManager, FortiAnalyzer, and FortiProxy. 📌Attackers possessing a FortiCloud account and a registered device can log into other devices registered to different accounts if FortiCloud SSO is enabled. 📌Fortinet temporarily disabled its FortiCloud Single Sign-On (SSO) service after confirming active exploitation of a zero-day authentication bypass vulnerability in multiple products. #CybersecurityNews #Fortinet

    Post summary

    Fortinet confirmed that CVE‑2026‑24858, a critical authentication bypass in FortiCloud SSO, is being actively exploited, prompting the company to temporarily disable the feature as a mitigation.

    1240100115.3K
    48.5K followersView on X
  • Sekurak@Sekurak
    Active Exploitation

    Dzień dobry i masakra. Czyli nowa krytyczna podatność w produktach Fortinet. CVE-2026-24858 ❌ Błąd klasy ominięcie uwierzytelnienia ❌ Jeśli miałeś włączone FortiCloud SSO na urządzeniach: FortiOS, FortiManager, FortiAnalyzer, FortiProxy, FortiWeb - to atakujący posiadający swoje urządzenie - mógł tak ot zalogować się i na twój sprzęt (!!!). Tj. przez wykorzystanie luki CVE-2026-24858 ❌ Podatność była wykorzystywana w realnych atakach ❌ Fortinet właśnie załatał problem

    Post summary

    CVE‑2026‑24858 is a critical authentication‑bypass flaw in Fortinet products that was actively exploited in the wild, and Fortinet has just issued a patch.

    7921001511.5K
    42.1K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 Yesterday, CISA added CVE-2026-24858 into their KEV list - an authentication bypass vulnerability in various Fortinet products, which enabled attackers with a FortiCloud account and a registered device to log into other devices registered to other accounts. Per Fortinet PSIRT: > This vulnerability was found being exploited in the wild by two malicious FortiCloud accounts, which were locked out on 2026-01-22. Around this timeframe we observed actor(s) abusing Forticloud pathways, attempting to inject SP-initiated SAML state into a FortiCloud SSO login path using the hostname "abdylla.turkmenabat.]tech". A notable data point in the payload is the SAML_SP_LOGIN_DUMP cookie, which Fortinet uses to persist and validate Service Provider-initiated SAML login state, ensuring that only authentication responses corresponding to a locally initiated session are accepted. This is a fairly strong indication of an attempt to replay or inject SAML authentication state via an "alternate authentication path", as CVE-2026-24858 is described to be abusable via, but this analysis should currently be treated as unverified. 185.246.188.74 belongs to a TOR exit node.

    Post summary

    The post reports CVE-2026-24858 as actively being exploited in the wild via FortiCloud authentication bypass, with attackers using SAML injection techniques.

    1164732312.6K
    6.0K followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2026-24858: Fortinet Auth Bypass currently under active exploitation. Attackers can bypass authentication to gain unauthorized access. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJGT1JUSU5FVC1Gb3J0aU1hbmFnZXIiIHx8IGFwcD0iRm9ydGlPUyIgfHwgYXBwPSJGT1JUSU5FVC1Gb3J0aUFuYWx5emVyIg%3D%3D 🎯1.1M+ Results are found on the https://en.fofa.info nearly year. FOFA Query: app="FORTINET-FortiManager" || app="FortiOS" || app="FORTINET-FortiAnalyzer" 🔖Refer: https://securityonline.info/under-attack-critical-fortinet-auth-bypass-cve-2026-24858-exploited-in-the-wild/ https://github.com/advisories/GHSA-2x38-48vp-w23x #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces that CVE-2026-24858 is being actively exploited in the wild, with no mention of patches or technical details.

    017263284.7K
    13.6K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🔧 Fortinet issues patch update for actively exploited FortiOS SSO flaw. The fix addresses CVE-2026-24858 (CVSS 9.4), an SSO authentication bypass that can allow cross-tenant device access when FortiCloud SSO is enabled. CISA has added the issue to its KEV list, setting a Jan 30 remediation deadline. 🔗 Details → https://thehackernews.com/2026/01/fortinet-patches-cve-2026-24858-after.html

    Post summary

    Fortinet released a patch for CVE-2026-24858, a high‑severity SSO authentication bypass that is actively exploited, with detailed vulnerability information but no PoC or exploit code disclosed.

    117161310.3K
    1.0M followersView on X
  • The Shadowserver Foundation@Shadowserver
    Active Exploitation

    CVE-2026-24858, a Fortinet authentication bypass vulnerability affecting multiple Fortinet products with FortiCloud SSO enabled has been added by @CISACyber to the KEV catalog. We share exposed Fortinet instances with FortiCloud SSO enabled daily in our feeds (~10 000 seen) https://t.co/vQsBOmLmaW

    Post summary

    CVE‑2026‑24858 is an authentication bypass affecting Fortinet FortiCloud SSO devices, listed in CISA’s KEV catalog, indicating active exploitation in the wild and a significant risk for exposed systems.

    115132126.2K
    21.6K followersView on X
  • Simo@SimoKohonen
    General

    A CVE-2026-24858 smoking gun...? Maybe maybe! 🧐👇

    Post summary

    The text references CVE‑2026‑24858 but contains no concrete information or claims about the vulnerability.

    13136719.9K
    2.8K followersView on X
  • 中島佑允(YusukeNakajima)@nakajimeeee
    Active Exploitation

    【脆弱性予測】CVE公開の11日前にインターネットは動き出す——GreyNoiseが1.48億セッション分析で事前兆候を実証 CiscoのCVE-2026-20127(CVSS 10.0、Five Eyes共同警告に引用されたゼロデイ)に対し、GreyNoiseセンサーは公式アドバイザリ公開前に8回の攻撃トラフィック急増を観測していた。最初の急増は公開39日前に発生した。新たな調査により、これは例外ではなく再現可能なパターンであることが判明した。 103日間にわたり、18のネットワーク機器ベンダーを対象とした276のベンダー固有タグで1億4780万セッションを追跡した結果、検出された104の急増イベントのうち68件がベンダー一致するCVEに先行しており、16のベンダーファミリーにわたる33の脆弱性に対応していた。統計的検定により、このパターンが偶然ではないことが確認された。 主要な知見として、リードタイムの中央値は11日で、49%の急増がCVE公開10日以内、78%が21日以内に発生している。セッション数が主要シグナルであり、IP数単独では弱い予測因子だが、両方が同時に急増すると信頼度は最高となりリードタイムは21日に延長される。 具体例では、SonicWall CVE-2026-0400は37日前から3日前まで6回の急増があり、ピーク時は中央値の69倍のセッション量を記録した。一方、Fortinet CVE-2026-24858(CVSS 9.4、ゼロデイ)の警告期間はわずか1日だった。分散型の急増は平均21.3日のリードタイムだったが、集中型ホスティングからの急増は7.5日に短縮された。 Mandiant M-Trends 2026は悪用までの平均時間がマイナスになったと報告し、VulnCheckは2025年のKEVの28.96%が公開日以前に悪用されていたと記録している。アドバイザリを待ってから行動するという従来モデルには測定可能なギャップが存在し、それを縮小するシグナルは既にGreyNoiseデータ内に可視化されている。 https://www.greynoise.io/blog/the-internet-changes-before-the-advisory-drops

    Post summary

    GreyNoise’s analysis demonstrates that many CVE-related attack surges begin weeks before official advisories, confirming that vulnerabilities are often exploited in the wild ahead of disclosure.

    05026152.6K
    2.9K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit 1⃣. CVE-2025-11730: RCE via DDNS configuration in ZYXEL ATP/USG Series https://github.com/rainpwn/exploits/blob/main/zyxel/rainpwn_cve-2025-11730_ddns_rce.py ]-> PoC https://rainpwn.blog/blog/cve-2025-11730 2⃣. A Deep Dive into CVE-2026-25049: n8n RCE https://blog.securelayer7.net/cve-2026-25049 3⃣. The RCE that AMD won’t fix https://web.archive.org/web/20260205155934/https://mrbruh.com/amd 4⃣. CVE-2026-24858: Fortinet FortiCloud SSO Admin Bypass https://github.com/absholi7ly/CVE-2026-24858-FortiCloud-SSO-Authentication-Bypass 5⃣. CVE-2026-25587, CVE-2026-25641: SandboxJS Sandbox Escape https://github.com/advisories/GHSA-66h4-qj4x-38xp

    Post summary

    The post lists multiple CVEs with available exploit code and PoC links, emphasizing the availability of functional attacks without indicating active exploitation or patches.

    13025131.2K
    3.1K followersView on X
  • Benjamin Harris@benwatchtowr
    General

    “Yet, he added: “As we’ve seen now for years, Fortinet and the ‘Fast & Furious’ franchise are apparently competing for the amount of sagas we can fit into one year. It’s unclear who will win.”” https://cyberscoop.com/ortinet-zero-day-cve-2026-24858-forticloud-sso-auth-bypass/

    Post summary

    The excerpt merely quotes a statement about Fortinet and a film franchise, providing no technical or exploit‑related information about CVE‑2026‑24858.

    1403243.4K
    429 followersView on X
  • Nicolas Krassas@Dinosn
    Patch

    Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected https://thehackernews.com/2026/01/fortinet-patches-cve-2026-24858-after.html

    Post summary

    Fortinet released a patch for CVE-2026-24858 following the detection of active exploitation of FortiOS SSO, but the post offers no PoC, exploit code, or detailed technical data.

    01002733.1K
    151.4K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    🚨 CISA WARNS: TWO MORE VULNERABILITIES ARE BEING ACTIVELY EXPLOITED CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation. The newly added vulnerabilities are: * CVE-2021-3129 — Laravel Framework Ignition File Upload Vulnerability A vulnerability affecting Laravel applications using vulnerable versions of the Ignition error-page component. Under certain configurations, an unauthenticated remote attacker can abuse Ignition functionality to achieve remote code execution. * CVE-2026-24858 — Fortinet FortiOS/FortiProxy/FortiSwitchManager/FortiManager Authentication Bypass Vulnerability An authentication-bypass vulnerability affecting multiple Fortinet products that could allow an unauthenticated attacker with a FortiCloud account and registered device to log into other devices registered to different accounts. CISA added both vulnerabilities to KEV because they meet one of the most important criteria defenders should pay attention to: ⚠️ EVIDENCE OF ACTIVE EXPLOITATION. Federal Civilian Executive Branch agencies are required under BOD 22-01 to remediate KEV vulnerabilities by CISA's specified deadlines. But KEV should not be treated as a federal-government-only patch list. ⚠️ Analyst Note: The Laravel vulnerability is particularly interesting because CVE-2021-3129 is more than five years old. Its appearance in KEV again demonstrates an uncomfortable reality: Attackers don't necessarily need new zero-days. Internet-facing systems running old, exploitable software can remain valuable targets YEARS after a vulnerability becomes publicly known. The Fortinet vulnerability highlights a different problem: compromise of edge infrastructure. Firewalls, VPN gateways, management appliances and other perimeter devices sit at highly privileged positions in enterprise networks. When vulnerabilities in these systems become actively exploited, remediation should be treated as a priority rather than simply another item in the vulnerability-management queue. If either product exists in your environment, don't prioritize solely by CVSS. Prioritize by exploitation. Source: CISA — August 31, 2026 https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog #DDW #CISA #KEV #Fortinet #CyberSecurity

    Post summary

    CISA has listed CVE-2021-3129 and CVE-2026-24858 as known exploited vulnerabilities in its KEV catalog, confirming that these CVEs are being actively attacked in the wild.

    0502716.8K
    206.6K followersView on X
  • Dr. John D. Johnson@johndjohnson
    Active Exploitation

    Hackers Exploit FortiGate Firewalls in Widespread Attacks to Steal Network Credentials Threat actors are primarily abusing several FortiGate vulnerabilities, including CVE-2025-59718, CVE-2025-59719, and the recently patched CVE-2026-24858. These flaws allow unauthorized users to bypass authentication controls and gain administrative-level access to vulnerable firewall devices. https://nuel.ink/qLGpkZ

    Post summary

    Report indicates attackers are actively exploiting FortiGate firewall vulnerabilities (CVE-2025-59718, CVE-2025-59719, CVE-2026-24858) to bypass authentication and gain admin access; CVE-2026-24858 has been recently patched.

    0801171.1K
    1.1K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortianalyzer---
Appfortinetfortimanager---
Appfortinetfortinac-f---
OSfortinetfortios---
Appfortinetfortiproxy---
Appfortinetfortiweb---
HWsiemensruggedcom_ape1808---
OSsiemensruggedcom_ape1808_firmware---

Explore more