logo

Actively Exploited Fortinet Zero-Day Gives Attackers Super-Admin Privileges

ID: 36c9145e-589e-58cb-8747-93ded9f731a4

STIX ID: report--36c9145e-589e-58cb-8747-93ded9f731a4

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-01-28

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Fortinet released a patch for CVE-2024-55591, a critical (CVSS 9.6) authentication-bypass in FortiOS/FortiProxy's jsconsole WebSocket that has been actively exploited to create admin accounts, modify device configurations, and use SSL VPN to access internal networks; researchers detailed a four-step exploit chain (pre-auth WebSocket, local_access_token session bypass, WebSocket Telnet race condition, and privilege selection) and Fortinet recommends following its upgrade path or applying provided workarounds and using non-guessable admin usernames.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.