<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/critical-forticloud-sso-zero-day-forces-emergency-service-disablement-at-fortinet-r50naqrng" -->

---
title: Critical FortiCloud SSO zero‑day forces emergency...
description: Fortinet disclosed a critical authentication bypass zero-day vulnerability (CVE-2026-24858, CVSS 9.4) affecting FortiCloud SSO that was actively exploited in...
canonical: https://daily.dev/posts/critical-forticloud-sso-zero-day-forces-emergency-service-disablement-at-fortinet-r50naqrng
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Critical FortiCloud SSO zero‑day forces emergency service disablement at Fortinet | daily.dev
og:description: Fortinet disclosed a critical authentication bypass zero-day vulnerability (CVE-2026-24858, CVSS 9.4) affecting FortiCloud SSO that was actively exploited in...
og:url: https://daily.dev/posts/critical-forticloud-sso-zero-day-forces-emergency-service-disablement-at-fortinet-r50naqrng
og:image: https://api.daily.dev/og/posts/R50NAQrNg.png
og:image:alt: Critical FortiCloud SSO zero‑day forces emergency service disablement at Fortinet
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical FortiCloud SSO zero‑day forces emergency service disablement at Fortinet

**[CSO Online](https://daily.dev/sources/csoonline)** · 4 min read · 0 upvotes · 0 comments

## Summary

Fortinet disclosed a critical authentication bypass zero-day vulnerability (CVE-2026-24858, CVSS 9.4) affecting FortiCloud SSO that was actively exploited in the wild. The company took emergency action by temporarily disabling FortiCloud SSO globally on January 26, then re-enabled it with server-side blocking that prevents vulnerable devices from authenticating until upgraded. Attackers used two malicious FortiCloud accounts to compromise fully patched FortiGate firewalls, FortiManager, and FortiAnalyzer devices, creating local admin accounts and downloading configuration files. CISA added the flaw to its KEV catalog, requiring federal agencies to patch by February 17, 2026. Most patches remain "upcoming" with only FortiOS 7.4.11 currently released, affecting versions 7.0 through 7.6 of multiple Fortinet products.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4123500/critical-forticloud-sso-zero%E2%80%91day-forces-emergency-service-disablement-at-fortinet.html>

## Similar posts on daily.dev

- [Fortinet SSO patch bypass gets a separate critical CVE](https://daily.dev/posts/fortinet-sso-patch-bypass-gets-a-separate-critical-cve-pbbljiqf4) · The Register · 0 upvotes · 0 comments

---

Tags: [#cloud](https://daily.dev/tags/cloud), [#cyber](https://daily.dev/tags/cyber), [#authentication](https://daily.dev/tags/authentication), [#zero-day](https://daily.dev/tags/zero-day), [#fortinet](https://daily.dev/tags/fortinet)

[View this post on daily.dev](https://daily.dev/posts/critical-forticloud-sso-zero-day-forces-emergency-service-disablement-at-fortinet-r50naqrng)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Critical FortiCloud SSO zero‑day forces emergency service disablement at Fortinet","url":"https://daily.dev/posts/critical-forticloud-sso-zero-day-forces-emergency-service-disablement-at-fortinet-r50naqrng","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/critical-forticloud-sso-zero-day-forces-emergency-service-disablement-at-fortinet-r50naqrng"},"datePublished":"2026-01-28T11:49:25.561Z","dateModified":"2026-02-27T12:10:28.545Z","description":"Fortinet disclosed a critical authentication bypass zero-day vulnerability (CVE-2026-24858, CVSS 9.4) affecting FortiCloud SSO that was actively exploited in...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ad7dfcade97b1870017d0fc051207d6d?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ad7dfcade97b1870017d0fc051207d6d?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/critical-forticloud-sso-zero-day-forces-emergency-service-disablement-at-fortinet-r50naqrng","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cloud,cyber,authentication,zero-day,fortinet","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Critical FortiCloud SSO zero‑day forces emergency service disablement at Fortinet"}]}
```

