logo

CVE-2022-40684 Critical Fortinet Authentication

ID: 3220c499-85ff-59a0-a33a-f246c2fcce0d

STIX ID: report--3220c499-85ff-59a0-a33a-f246c2fcce0d

Feed Name: Arctic Wolf Blog

Threat Score
85/100

Date Published: 2022-10-14

Date Updated: 2026-04-27

...
...

**Executive Summary:** Arctic Wolf observed active exploitation of CVE-2022-40684 (a critical remote authentication bypass in FortiOS, FortiProxy, and FortiSwitchManager) enabling attackers to download device configuration files, create privileged accounts, and run scripts; the advisory lists affected and fixed versions and provides prioritized mitigations including upgrading firmware, disabling external admin access, enforcing MFA, performing clean device reinstalls, rotating credentials, and revoking exposed certificates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.