Fortinet disclosed two critical vulnerabilities affecting FortiWeb and FortiManager, both of which have been exploited in the wild and can lead to full device compromise. In FortiWeb, multiple versions are affected by an unauthenticated SQL injection flaw that lets attackers send crafted HTTP or HTTPS requests to execute unauthorized SQL commands, bypass access controls, read sensitive configuration and user data, alter or delete database records, and potentially escalate to complete system takeover. Fortinet advised customers to upgrade immediately to fixed releases or disable the HTTP/HTTPS management interface as a temporary workaround.
In FortiManager, the critical flaw tracked as CVE-2024-47575 allows unauthenticated remote code execution and remote command execution, with exploitation observed globally and against Finnish organizations. A successful attack can give intruders control of vulnerable FortiManager systems and expose connected device configuration data and passwords. Fortinet issued patches for most affected branches, while FortiManager Cloud 6.4 has no fix and must be upgraded; the company also warned that if exploitation is suspected, patching alone is insufficient and organizations should perform a full incident investigation using Fortinet’s compromise-assessment guidance.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Fortinet recommended immediate upgrades to fixed FortiWeb versions for affected 7.0, 7.2, 7.4, and 7.6 branches. As a workaround, organizations unable to patch were advised to disable the HTTP/HTTPS management interface.
Fortinet disclosed a critical SQL injection vulnerability affecting multiple FortiWeb versions that allows unauthenticated attackers to execute unauthorized SQL commands via crafted HTTP or HTTPS requests. The issue was reported as actively exploited and could lead to access-control bypass, data exposure or modification, and possible full system compromise.
The Finnish National Cyber Security Centre reported exploitation attempts against Finnish organizations targeting the FortiManager flaw CVE-2024-47575. Successful exploitation could allow takeover of vulnerable FortiManager systems and theft of sensitive configuration data and passwords.
Fortinet released security updates for a critical FortiManager vulnerability, CVE-2024-47575, that allows unauthenticated remote code execution and remote command execution. The company said the flaw had already been exploited in the wild globally and published compromise-checking and mitigation guidance.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.