Simo[verified]@SimoKohonenGeneral
The tweet questions the relevance of Fortinet CVE-2026-24858, noting that attackers can misuse a valid FortiCloud session on other devices, but offers no PoC, exploit code, patch, or evidence of active exploitation.
Juan Carlos Ortiz 🛡️ Ciberseguridad para Empresas[verified]@CycuraMXActive Exploitation
Fortinet reports that CVE-2026-24858 is actively exploited through FortiCloud SSO, enabling attackers to control firewalls without password and gain network access; immediate patching and configuration review are required.
Hunter[verified]@HunterMappingActive Exploitation
Fortinet’s authentication bypass vulnerability (CVE‑2026‑24858) is actively being exploited in the wild according to cited reports, though the notice does not provide a PoC, exploit code, or patch information.
BleepingComputer[verified]@BleepinComputerActive Exploitation
CVE-2026-24858 is an actively exploited FortiCloud SSO authentication bypass that enables rogue admin and VPN accounts and theft of firewall configurations. No patch is yet available, only mitigations have been deployed.
Cyber Security News[verified]@The_Cyber_NewsActive Exploitation
Fortinet confirmed that CVE‑2026‑24858, a critical authentication bypass in FortiCloud SSO, is being actively exploited, prompting the company to temporarily disable the feature as a mitigation.
Sekurak[verified]@SekurakActive Exploitation
CVE‑2026‑24858 is a critical authentication‑bypass flaw in Fortinet products that was actively exploited in the wild, and Fortinet has just issued a patch.
FOFA[verified]@fofabotActive Exploitation
The post announces that CVE-2026-24858 is being actively exploited in the wild, with no mention of patches or technical details.
Simo[verified]@SimoKohonenGeneral
The text references CVE‑2026‑24858 but contains no concrete information or claims about the vulnerability.