CISA Warns of Fortinet FortiOS Authentication Bypass Vulnerability Exploited in Wild
ID: 12f6bc85-d33e-52a6-b9a0-b06ce2850d41
STIX ID: report--12f6bc85-d33e-52a6-b9a0-b06ce2850d41
Feed Name: cybersecurityNews.com
CISA warns of a high-severity authentication bypass in Fortinet FortiOS and FortiProxy (CVE-2025-24472, CVSS 8.1) that enables remote attackers to obtain super-admin privileges via crafted CSF proxy requests; the flaw affects multiple 7.0 and 7.2 releases, has been observed in active ransomware campaigns, and is listed in CISA's KEV catalog. Fortinet published patches (FortiOS 7.0.17+/FortiProxy 7.0.20/7.2.13+) and CISA recommends applying vendor mitigations, disabling HTTP/HTTPS admin interfaces or using IP-based restrictions as temporary measures while monitoring for suspicious admin activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
