#fortios

[ follow ]
fromThe Hacker News
1 day ago

Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation Detected

Fortinet has begun releasing security updates to address a critical flaw impacting FortiOS that has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2026-24858 (CVSS score: 9.4), has been described as an authentication bypass related to FortiOS single sign-on (SSO). The flaw also affects FortiManager and FortiAnalyzer. The company said it's continuing to investigate if other products, including FortiWeb and FortiSwitch Manager, are impacted by the flaw.
Information security
Information security
fromTechzine Global
1 month ago

Attackers exploit five-year-old Fortinet vulnerability

A critical FortiOS SSL VPN flaw (CVE-2020-12812) allows 2FA bypass via username changes; patches have existed since 2020 but many systems remain unpatched.
[ Load more ]