Exploited Vulnerabilities Daily
🌐 English

Home › Fortinet

CVE-2026-24858: Fortinet Multiple Products

EPSS85.7%No. 540 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV31
Same product6
FieldValue
VendorFortinet
ProductMultiple Products
NameFortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
Added to KEV2026-01-27
US federal due date2026-01-30
Ransomware useUnknown
CWECWE-288

CISA description

Fortinet FortiAnalyzer, FortiManager, FortiOS, and FortiProxy contain an authentication bypass using an alternate path or channel that could allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2025-25249Fortinet Multiple Products2026-09-093.8%Unknown
CVE-2025-59718Fortinet Multiple Products2025-12-1668.2%Unknown
CVE-2025-32756Fortinet Multiple Products2025-05-1429.8%Unknown
CVE-2024-23113Fortinet Multiple Products2024-10-0961.7%Unknown
CVE-2022-40684Fortinet Multiple Products2022-10-1199.9%Known

NVD — CVE-2026-24858

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Fortinet Multiple Products vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-01-27.