logo

FortiOS Vulnerability Allows Super-Admin Privilege Escalation – Patch Now!

ID: ca96fbe4-9972-51d0-bb98-040b6958645b

STIX ID: report--ca96fbe4-9972-51d0-bb98-040b6958645b

Feed Name: HackRead

Threat Score
72/100

Date Published: 2025-02-13

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Fortinet disclosed a high-severity FortiOS Security Fabric vulnerability (CVE-2024-40591, CVSSv3 8.0) that allows an authenticated administrator with Security Fabric permissions to escalate to super-admin if they connect to a compromised upstream FortiGate. Multiple FortiOS branches are affected (7.6.0; 7.4.0–7.4.4; 7.2.0–7.2.9; 7.0.0–7.0.15; all 6.4 versions) and Fortinet has released patched versions (7.6.1, 7.4.5, 7.2.10, 7.0.16 or migration for 6.4); administrators are urged to apply updates immediately to prevent potential network-wide compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.