Attackers have been actively targeting internet-exposed Fortinet FortiGate management interfaces to seize administrative control of firewalls, with reporting tying the activity to exploitation of CVE-2024-55591 and a related authentication weakness, CVE-2025-24472. Fortinet said the primary flaw affects FortiOS and FortiProxy and stems from improper authentication in the Node.js websocket module, allowing an unauthenticated remote attacker to obtain super-admin access and full control of vulnerable devices.
Observed intrusions included the creation of new administrator accounts, adding those accounts to SSL VPN groups, changing firewall policies, and using the compromised appliances to pivot into networks that were otherwise protected behind the VPN perimeter. Security guidance accompanying the disclosures urged organizations to apply Fortinet patches immediately, disable or restrict public exposure of management interfaces, harden FortiOS devices, and review logs for signs of compromise tied to the broader campaign against exposed firewall consoles.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Fortinet released security updates to address CVE-2024-55591, an actively exploited critical authentication flaw, and CVE-2025-24472, another authentication weakness that could allow full system control via crafted CFS proxy requests. The updates were issued in response to the risk to FortiOS and FortiProxy devices.
During the exploitation campaign, attackers created new administrative accounts, added them to SSL VPN groups, modified firewall rules, and used those changes to pivot into protected VPN networks. These actions were described as observed attacker behavior on compromised devices.
According to Fortinet reporting cited by CSIRT.SK, exploitation of CVE-2024-55591 against internet-exposed FortiOS and FortiProxy management interfaces has been observed since at least mid-November 2024. The activity involved gaining super-admin access and full control of affected devices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.