CVE-2026-24858

● KEV CRITICAL

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2...

Affects 7 products across 2 vendors.

BCS9.64
CVSS 3.19.8
EPSS85.8%
Percentile100th
PatchPatched
KEV Added2026-01-27
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-288: CWE-288
Related Attack Patterns (CAPEC)
CAPEC-127 Directory Indexing
via CWE-288
CAPEC-665 Exploitation of Thunderbolt Protection Flaws
via CWE-288

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A critical Authentication Bypass vulnerability exists in multiple versions of Fortinet products, including FortiAnalyzer, FortiManager, FortiOS, FortiProxy, and FortiWeb. This vulnerability allows an attacker with a FortiCloud account and a registered device to log into other devices registered to different accounts if FortiCloud SSO authentication is enabled. The CVSS score is 9.8, indicating a high severity level. Immediate action is required to mitigate the risk of unauthorized access and potential compromise of affected systems.

BSID: BS-2026-GLOBAL-072918-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-24858?
A critical Authentication Bypass vulnerability exists in multiple versions of Fortinet products, including FortiAnalyzer, FortiManager, FortiOS, FortiProxy, and FortiWeb. This vulnerability allows an attacker with a FortiCloud account and a registered device to log into other devices registered to different accounts if FortiCloud SSO authentication is enabled. The CVSS score is 9.8, indicating a high severity level. Immediate action is required to mitigate the risk of unauthorized access and pot
What is the CVSS score for CVE-2026-24858?
CVE-2026-24858 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 85.8%.
Is CVE-2026-24858 actively exploited?
Yes. CVE-2026-24858 is in the CISA KEV catalog (added 2026-01-27). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2026-24858?
Priority: IMMEDIATE. Advisory: https://fortiguard.fortinet.com/psirt/FG-IR-26-060 PSIRT: [email protected]
What systems are affected by CVE-2026-24858?
CVE-2026-24858 affects: Fortinet, Fortinet, Fortinet, Fortinet, Fortinet, Siemens, Siemens.
What NERC-CIP standard applies to CVE-2026-24858?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it allows unauthorized access to critical cyber assets, which could lead to the compromise of the asset's integrity and availability.
What IEC 62443 requirement maps to CVE-2026-24858?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves an authentication bypass, which can lead to unauthorized access to the system. Proper authentication mechanisms are essential to ensure that only authorized personnel can access the system, maintaining the confidentiality, integrity, and availability of the control system.
Vulnerability Details
CVE IDCVE-2026-24858
BSIDBS-2026-GLOBAL-072918-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2026-01-27
Last Modified2026-05-12
ICS Relevance85%
Weakness (CWE)
Verticals
ICS-OT
Domains
NETWORK-INFRA
SourceNVD
Official Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability can be exploited by an attacker with a FortiCloud account and a registered device. If FortiCloud SSO authentication is enabled on the target device, the attacker can bypass the authentication mechanism and gain unauthorized access to the device. This can lead to full control over the device, allowing the attacker to perform actions such as modifying configurations, accessing sensitive data, and disrupting operations.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Fortinet Fortimanager
Fortinet Fortianalyzer
Fortinet Fortiproxy
Fortinet Fortios
Fortinet Fortiweb
Siemens Ruggedcom Ape1808
Siemens Ruggedcom Ape1808 Firmware
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 202 Days
CISA KEV● Active Exploitation Confirmed (added 2026-01-27)
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict access controls and monitor FortiCloud SSO authentication attempts. Ensure that only authorized users can register devices and that device registration is tightly controlled. Regularly review logs for suspicious activity and consider implementing multi-factor authentication for additional security.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it allows unauthorized access to critical cyber assets, which could lead to the compromise of the asset's integrity and availability.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves an authentication bypass, which can lead to unauthorized access to the system. Proper authentication mechanisms are essential to ensure that only authorized personnel can access the system, maintaining the confidentiality, integrity, and availability of the control system.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash62f01a8b5e5185882d20b19f7bb6281318689e620fb345e87bba6b424b7cceda1566936c5805704ab1084e8d671386a64d186ce75b9430bbb8076e9560bd5df3
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2024-47575 9.8 A missing authentication for critical function in FortiManager 7.6.0, FortiMa... CVE-2023-47539 9.8 An improper access control vulnerability in FortiMail version 7.4.0 configure... CVE-2015-3616 9.8 SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2... CVE-2016-4573 9.8 Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-...
View all Fortinet CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2026-24858 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →