RaqibCTI
CVE

CVE-2026-24858

P2
Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Fortinet · Multiple Products
Date added (CISA)
2026-01-27
Remediation due
2026-01-30
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date
Associated with
Related to
  • Lazarus Group (TraderTraitor cluster) / APT38 / BlueNoroff · SPECTREcampaignCorrelated cluster2026-09-16

Description

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Source: NVD ↗ · CISA KEV Catalog ↗