logo

FortiManager critical vulnerability under active attack

ID: 9f597fb0-b615-5411-a679-33bd6a0437e3

STIX ID: report--9f597fb0-b615-5411-a679-33bd6a0437e3

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-10-23

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Fortinet disclosed CVE-2024-47575, a critical (CVSS 9.8) missing-authentication vulnerability in FortiManager that allows remote unauthenticated code execution; the flaw is being actively exploited in the wild, CISA added it to its Known Exploited Vulnerabilities catalog, and investigators (Mandiant) attribute mass exfiltration of FortiGate configuration data to a new cluster tracked as UNC5820. Fortinet has published IOCs (including four malicious IPs), mitigation guidance and urged immediate patching of affected FortiManager instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.