Fortinet reported limited active exploitation of CVE-2024-21762, a critical out-of-bounds write vulnerability in the sslvpnd component of FortiOS SSL-VPN. An unauthenticated remote attacker can trigger denial of service or execute arbitrary code, potentially taking control of a vulnerable FortiGate appliance. The vulnerability is rated CVSS 9.6, and public proof-of-concept exploit code became available.
Organizations running affected FortiOS 7.4 and earlier releases should apply Fortinet’s security updates immediately; FortiOS 7.6 is not affected. The Dutch National Cyber Security Centre assessed the issue as High/High due to its impact, active exploitation, and expected exploit availability, and advised disabling SSL-VPN as a temporary mitigation where immediate patching is not possible.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
A proof of concept was published for CVE-2024-21762, the FortiOS SSL-VPN vulnerability with a CVSS score of 9.6.
CVE-2024-23113 was disclosed as a CVSS 9.8 format-string flaw in Fortinet's fgfmd daemon that can allow unauthenticated remote code or command execution. The issue affects specified FortiOS, FortiProxy, and FortiPAM releases; organizations were advised to upgrade to fixed versions or remove FGFM access from interfaces as an interim mitigation.
Researchers disclosed a pre-authentication exploit chain for CVE-2024-21762 that turns a constrained two-byte stack overwrite in FortiGate SSL-VPN chunked-request parsing into remote code execution. The tested exploit used heap grooming, a forged SSL structure, return-oriented programming, and Node.js to obtain a reverse shell on the targeted firmware version.
Fortinet released security updates for FortiOS 7.4 and earlier versions to remediate CVE-2024-21762. FortiOS 7.6 was identified as unaffected, and disabling SSL-VPN was recommended as a temporary workaround when immediate patching was not possible.
Fortinet reported that CVE-2024-21762, a critical FortiOS SSL-VPN flaw in the sslvpnd process, had been actively exploited on a limited basis. The vulnerability can allow unauthenticated attackers to cause denial of service or execute arbitrary code on affected appliances.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourcefortiguard.com
Open sourcefortiguard.com
Open sourcencsc.nl
Open sourcewiz.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.