Fortinet FortiManager is affected by a critical pre-authentication remote code execution vulnerability tracked as CVE-2024-47575, with public reporting and government advisories identifying the flaw as a high-severity risk to exposed management infrastructure. A technical write-up described the issue as a pre-auth RCE chain in FortiManager, indicating that an unauthenticated attacker could potentially reach code execution without valid credentials.
COLCERT separately issued an alert on CVE-2024-47575, reinforcing the vulnerability's critical status and highlighting it for defenders in enterprise and government environments that rely on FortiManager for centralized administration of Fortinet devices. The combined reporting points to an urgent need for organizations using FortiManager to identify affected deployments, prioritize vendor guidance, and accelerate patching or other mitigations for internet-accessible systems.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
A technical blog post described CVE-2024-47575 as a pre-authentication remote code execution chain affecting Fortinet FortiManager and pointed readers to a post titled "Hop-Skip-FortiJump-FortiJump-Higher" for full details.
COLCERT published advisory AL-2510-053 for a critical FortiManager vulnerability identified as CVE-2024-47575. The visible content does not include technical exploitation details or affected version information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.