logo

Fortinet Zero-Day Bug May Lead to Arbitrary Code Execution

ID: b8ebf26d-573a-5785-9985-2b10c4dcc3b2

STIX ID: report--b8ebf26d-573a-5785-9985-2b10c4dcc3b2

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-04-14

Date Updated: 2026-05-05

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

A threat actor posted on a Dark Web forum claiming a FortiGate zero-day that enables unauthenticated remote code execution and full control of affected devices, including exfiltration of FortiOS configs and credentials. Fortinet concurrently released an advisory describing exploitation of known FortiOS/FortiProxy vulnerabilities (CVE-2022-42475, CVE-2023-27997, CVE-2024-21762), remediation guidance for those CVEs, and reports indicate over 14,000 devices may have been compromised, while clear mitigations for the alleged zero-day are not provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.