logo

New Fortinet RCE bug is actively exploited, CISA confirms

ID: 3c4b61c4-816d-5b41-8d11-ea2310e943cd

STIX ID: report--3c4b61c4-816d-5b41-8d11-ea2310e943cd

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-02-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA confirmed active exploitation of a critical Fortinet RCE vulnerability (CVE-2024-21762) affecting FortiOS and FortiProxy; Fortinet released a patch and U.S. federal agencies were ordered to secure affected devices within seven days. The report also covers confusing FortiSIEM CVE disclosures and notes past exploitation of Fortinet flaws by threat actors (e.g., Volt Typhoon) and ransomware groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.