logo

Fortinet warns of active campaign exploiting bug in FortiManager products

ID: 54b2fa2f-a881-582f-92f5-21e15ca50d5e

STIX ID: report--54b2fa2f-a881-582f-92f5-21e15ca50d5e

Feed Name: CyberScoop

Threat Score
88/100

Date Published: 2024-10-24

Date Updated: 2026-04-21

Author: Christian Vasquez

...
...

Fortinet and Mandiant report active exploitation of a critical FortiManager zero-day (CVE-2024-47575, CVSS ~9.8) that permits unauthenticated remote code execution and management of connected FortiGate devices; investigations have identified dozens of affected organizations, credential and configuration exfiltration by actor cluster UNC5820, and widespread internet-exposed devices, prompting CISA and vendors to urge patching and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.