Fortinet disclosed multiple critical vulnerabilities in FortiOS and related products, including an authentication bypass in FortiOS and FortiProxy that can grant attackers super-admin privileges and is being actively exploited in the wild. The flaw can be triggered through specially crafted requests to the Node.js websocket module and affects FortiOS 7.0.0 through 7.0.16, FortiProxy 7.2.0 through 7.2.12, and FortiProxy 7.0.0 through 7.0.19. Organizations were told to upgrade to FortiOS 7.0.17+, FortiProxy 7.2.13+, or FortiProxy 7.0.20+, and to apply Fortinet’s recommended mitigations immediately.
Separate Fortinet advisories also warned of critical flaws CVE-2024-21762 and CVE-2024-23113, affecting FortiOS, FortiProxy, FortiPAM, and FortiSwitchManager. CVE-2024-21762 carries a CVSS 9.6 rating, while CVE-2024-23113 is rated CVSS 9.8; both require urgent patching to fixed versions identified by Fortinet. Fortinet and national cyber authorities said defenders should prioritize upgrades across exposed appliances, and for CVE-2024-21762, disabling the SSL VPN feature can reduce exposure until patches are applied.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Fortinet disclosed a critical authentication bypass vulnerability in FortiOS and FortiProxy that can grant an attacker super-admin privileges via specially crafted requests to the Node.js websocket module. Fortinet said the flaw was being actively exploited in the wild and advised customers to upgrade to fixed versions or apply recommended mitigations.
Fortinet disclosed multiple critical vulnerabilities affecting FortiOS and other products, notably CVE-2024-21762 and CVE-2024-23113, and identified affected and fixed versions. The guidance included urgent patching and a mitigation note that disabling SSL VPN could help reduce exposure to CVE-2024-21762.
A vulnerability notice reported a critical flaw affecting FortiOS, FortiOS-6K7K, and FortiProxy across multiple release branches, and listed minimum patched versions required for remediation. Organizations were advised to upgrade to fixed releases including FortiOS 7.4.0/7.2.5/7.0.12 and FortiProxy 7.2.4/7.0.10/2.0.13 or later.
A notice warned of critical vulnerabilities in FortiOS, FortiProxy, FortiSwitchManager, and FortiTester and provided fixed versions for affected release lines. It also advised organizations unable to patch immediately to restrict network access to management interfaces using firewall rules.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
kyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.