logo

CVE-2024-55591: The FortiOS Authentication Bypass That Handed Attackers the Keys to the Kingdom

ID: bbb1627c-4725-5104-a45a-a9ecb984ced5

STIX ID: report--bbb1627c-4725-5104-a45a-a9ecb984ced5

Feed Name: NoHackie

Threat Score
90/100

Date Published: 2026-02-26

Date Updated: 2026-04-19

...
...

This report details CVE-2024-55591, a critical Node.js WebSocket authentication-bypass in FortiOS/FortiProxy that allowed unauthenticated remote attackers to obtain super-admin CLI access; it documents active exploitation since late 2024, a public PoC, the subsequent weaponization by the NightSpire ransomware group (data exfiltration and double-extortion), observed campaign phases and indicators, and prescribes urgent mitigations including patching, restricting management access, and incident response audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.