logo

New Fortinet RCE flaw in SSL VPN likely exploited in attacks

ID: 4ac70cbd-0303-512b-8960-5f524e19987c

STIX ID: report--4ac70cbd-0303-512b-8960-5f524e19987c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-08

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Fortinet disclosed a critical FortiOS SSL VPN vulnerability (CVE-2024-21762, severity 9.6) — an unauthenticated out-of-bounds write that can lead to remote code execution — and published upgrade paths and a mitigation (disable SSL VPN) for affected versions; while there are no confirmed reports of active exploitation for this CVE, the advisory references the high-risk context of FortiOS-targeting actors (including the Volt Typhoon APT and the COATHANGER RAT) and urges immediate patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.