logo

CISA and Fortinet Warns of New FortiOS Zero-Day Flaws

ID: 86747f56-eee1-5950-9f8f-d54662e4f17d

STIX ID: report--86747f56-eee1-5950-9f8f-d54662e4f17d

Feed Name: HackRead

Threat Score
90/100

Date Published: 2024-02-10

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Fortinet disclosed two critical FortiOS vulnerabilities (CVE-2024-21762 — out-of-bounds write in SSL VPN, CVSS 9.6, actively exploited; and CVE-2024-23113 — format string flaw in Forti/gate-to-FortiManager protocol, CVSS 9.8) affecting multiple FortiOS versions; Fortinet released patches (except for legacy 6.0) and CISA added CVE-2024-21762 to its Known Exploited Vulnerabilities list, while the report highlights concerns about exploitability, imminent PoC disclosure, and ties to China-linked actor Volt Typhoon exploiting network appliance vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.