logo

Fortinet's week to forget: Critical vulns, disclosure screw-ups, and <em>that</em> toothbrush DDoS attack claim

ID: 7f829e24-2975-5870-8156-ef9e0cd01739

STIX ID: report--7f829e24-2975-5870-8156-ef9e0cd01739

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2024-02-09

Date Updated: 2026-04-26

Author: Connor Jones

...
...

The Register reports a string of Fortinet security problems, most critically CVE-24-21762 (a 9.6-severity out-of-bounds write in FortiOS SSL VPN enabling remote unauthenticated RCE with signs of in-the-wild exploitation). The article details affected FortiOS versions (including unsupported releases), available patches and limited workaround (disable SSL VPN), alongside additional disclosed CVEs, disclosure mishandling by the vendor, and reports of Chinese actors exploiting FortiGate with custom malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.