Fortinet patched CVE-2024-47575, a critical FortiManager zero-day in the fgfmd API that allows unauthenticated attackers to inject commands, execute arbitrary code, access sensitive data, and potentially take control of FortiManager and managed devices. The flaw carries a CVSS 9.8 rating, and Fortinet said it had already warned customers and issued temporary mitigation guidance before releasing fixed versions for FortiManager and FortiManager Cloud.
Mandiant reported that the vulnerability was exploited in the wild from at least June 27, 2024, with mass exploitation observed in October and more than 50 potentially compromised internet-exposed FortiManager appliances identified across multiple industries. The activity, tracked as UNC5820 and also referenced by Fortinet as FG-IR-24-423, involved staging and exfiltrating configuration data from managed FortiGate devices, including detailed appliance configurations and FortiOS256-hashed user passwords; defenders were urged to upgrade immediately, restrict administrative exposure, tighten access controls, and review logs and published indicators of compromise.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Mandiant publicly reported that the FortiManager zero-day exploitation was linked to a newly tracked threat cluster, UNC5820. It also warned that stolen configuration data could support further compromise and lateral movement, although no such follow-on activity had yet been observed.
In October 2024, Mandiant and Fortinet investigated mass exploitation of FortiManager appliances and identified more than 50 potentially compromised devices across multiple industries. Attackers staged and exfiltrated configuration data from managed FortiGate devices, including appliance configurations and FortiOS256-hashed user passwords.
Fortinet released fixes for the critical FortiManager zero-day CVE-2024-47575, a missing authentication flaw in the fgfmd API that can enable unauthenticated command injection and code execution. The company recommended immediate upgrades to fixed FortiManager and FortiManager Cloud versions.
Fortinet had been warning customers about the FortiManager vulnerability and providing temporary mitigation guidance since 2024-10-13. The guidance preceded the availability of patched versions.
Mandiant observed exploitation of CVE-2024-47575 as early as 2024-06-27. The activity was later attributed to the newly tracked threat cluster UNC5820.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.