← Back to knowledge base
critical

Troubleshooting the FortiOS critical-vulnerability upgrade prompt for FG-IR-25-647 and FG-IR-26-060

Confirmed 9/22/2026

Problem

After an administrator logs in to a FortiGate running affected firmware, the GUI may prompt for a firmware upgrade because the installed build is associated with the critical FortiCloud SSO login authentication-bypass vulnerabilities documented in FG-IR-25-647 and FG-IR-26-060.

Symptoms

The FortiGate GUI displays a critical-vulnerability warning after login and offers options to upgrade or skip. The warning recommends upgrading within one week; it does not schedule or trigger an automatic reboot. The prompt may not appear immediately after startup because the vulnerability check takes time. FortiCloud SSO attempts from unpatched devices may also be blocked with “Web Page Blocked! Attack ID: 20000021”.

Environment

FortiGate devices on which the FortiCloud SSO administrative-login feature is enabled. In FortiOS v7.4 and later, the critical-vulnerability check requires only firmware entitlement. Fortinet disabled FortiCloud SSO access from vulnerable, unpatched devices on the FortiCloud side beginning January 26, 2026.

FortiOS version

FortiGate v7.4.10 and earlier; FortiOS v7.6.5 and earlier.

Root Cause

At startup, FortiOS compares its build number with PSIRT definitions for known critical vulnerabilities. When the installed firmware matches a vulnerable release, FortiOS presents the warning after administrator login. The warning is determined by firmware version, so it remains applicable even after FortiCloud SSO login is disabled. FG-IR-25-647 and FG-IR-26-060 affect devices with FortiCloud SSO login enabled.

Solution

  1. Review the PSIRT advisories for FG-IR-25-647, “Multiple Fortinet Products' FortiCloud SSO Login Authentication Bypass,” and FG-IR-26-060, “Administrative FortiCloud SSO authentication bypass.”

  2. Upgrade the FortiGate to a non-affected FortiOS release by following the supported upgrade path. The GUI warning permits the administrator to start the upgrade or skip it temporarily.

  3. Until the upgrade is completed, disable FortiCloud SSO administrative login. In the GUI, log in to the FortiGate, go to Settings, and disable FortiCloud SSO. Depending on the firmware release, this option may be labeled Allow administrative login using FortiCloud SSO.

  4. Alternatively, disable the feature from the CLI:

config system global
    set admin-forticloud-sso-login disable
end

This command does not affect production traffic or other FortiGate functions. It only prevents administrators from authenticating to the device through FortiCloud Single Sign-On.

  1. If necessary, temporarily clear the upgrade warning with the following command:
diagnose report-runner vuln-clean

This only dismisses the warning and does not remediate the vulnerability. The banner returns after the Security Rating Report communicates with FortiGuard Servers; this check runs automatically every 4 hours.

  1. If the recurring banner must be prevented, disable the scheduled FortiGuard Security Rating checks according to the Fortinet procedure for disabling scheduled Security Rating checks. This does not replace upgrading the firmware or disabling FortiCloud SSO.

Verification

Confirm that FortiCloud SSO or Allow administrative login using FortiCloud SSO is disabled and that administrators can no longer log in through FortiCloud SSO. Verify that the FortiGate has been upgraded to a release identified as non-affected by the latest PSIRT advisory. Do not use disappearance of the GUI warning as proof of remediation: the warning is firmware-version based, may remain after SSO is disabled, and can be temporarily cleared without fixing the vulnerability.

Tags

No tags yet.

Community rating

— / 5 (0)

Discussion (0)

    No comments yet.