logo

CISA says critical Fortinet RCE flaw now exploited in attacks

ID: b9753487-e50c-5020-9adf-cfe231045366

STIX ID: report--b9753487-e50c-5020-9adf-cfe231045366

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-10-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA warns that CVE-2024-23113, a critical unauthenticated remote code execution flaw in Fortinet's fgfmd daemon affecting FortiOS, FortiPAM, FortiProxy, and FortiWeb, is being actively exploited; Fortinet issued patches and mitigations in February, and CISA added the issue to its Known Exploited Vulnerabilities catalog requiring federal agencies to remediate within three weeks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.