logo

Security alert: critical Fortigate remote code execution vulnerability

ID: d18eae7a-be62-5ac3-896b-795c04816633

STIX ID: report--d18eae7a-be62-5ac3-896b-795c04816633

Feed Name: Expel Blog

Threat Score
88/100

Date Published: 2023-06-13

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

Fortinet released a June 9, 2023 patch for CVE-2023-27997, a critical (CVSS 9.8) unauthenticated remote code execution vulnerability affecting FortiGate firewalls when SSL‑VPN is enabled; the advisory urges immediate patching, disabling SSL‑VPN if unused, following Fortinet hardening guidance, and using vulnerability scanners to verify remediation, noting prior exploitation of FortiGate flaws by state-linked actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.