logo

Critical Fortinet Vulnerability Draws Fresh Attention

ID: ee2090a1-2b4b-554e-9e74-4688b3b40422

STIX ID: report--ee2090a1-2b4b-554e-9e74-4688b3b40422

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-03-19

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Fortinet disclosed two critical authentication-bypass vulnerabilities (CVE-2025-24472 and CVE-2024-55591) that allow unauthenticated attackers to achieve super-admin access on FortiOS and FortiProxy devices; CISA added at least one to its Known Exploited Vulnerabilities catalog. Security vendors report active exploitation in the wild, with a ransomware operator tracked as Mora_001 leveraging the flaws for initial access, privilege escalation, persistence (creating admin accounts, scheduled scripts, syncing backups), lateral movement, data exfiltration, and deployment of a ransomware variant called "SuperBlack"—prompting urgent patching and mitigation for exposed management interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.