CVE-2026-24858
Fortinet — Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability
What EVULNABLE says
EVULNABLE Risk · priority
86/100
Immediate
Intelligence coverage 75/90 — no pre-patch disclosure data
The priority band answers “how soon”, not “how bad” — see Methodology for what it weighs and where it abstains.
The evidence behind it
| Measure | Value | Source |
|---|---|---|
| CVSS base score | 9.8 | NVD |
| FIRST EPSS | 0.861 (99.72nd pctl) | FIRST |
| Actively exploited | Confirmed | CISA KEV |
| Ransomware campaign use | Unknown or none | CISA KEV |
| CISA remediation deadline | 2026-01-30 — Overdue by 7 months | CISA KEV |
What CISA says to do
- Please adhere to Fortinet's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible Fortinet products affected by this vulnerability. Apply any final mitigations provided by the vendor as soon as they become available. For more information please see ↗
- www.fortinet.com/…/analysis-of-sso-abuse-on-fortios ↗
- nvd.nist.gov/…/CVE-2026-24858 ↗
The primary records
This page is an opinion about urgency. Where it and a source of record disagree, the source of record is the record.