The patches address four critical vulnerabilities: CVE-2025-40552 and CVE-2025-40554, which allow remote authentication bypass, CVE-2025-40553, a remote code execution (RCE) flaw due to untrusted data deserialization, and CVE-2025-40551, another RCE vulnerability.
Fortinet has issued emergency updates to address the critical FortiCloud SSO authentication bypass vulnerability, tracked as CVE-2026-24858, after momentarily deactivating FortiCloud SSO and blocking FortiCloud accounts observed in zero-day intrusions earlier this month, reports SecurityWeek.
The inclusion of these vulnerabilities in CISA's KEV catalog mandates federal agencies to address them by February 16, 2026, under Binding Operational Directive 22-01.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.