Fortinet released updates for an actively exploited FortiOS SSO authentication bypass flaw, CVE-2026-24858, now listed by CISA in KEV.
Issued on behalf of QSE - Quantum Secure Encryption Corp.
Fortinet has released patches for CVE-2026-24858, an authentication bypass exploited in the wild to compromise devices.
CISA added the flaw to its KEVs catalog as Fortinet warned that patches for most affected versions remain “upcoming,” even though vulnerable devices can no longer use cloud SSO until upgraded.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results