logo

Burning Zero Days: FortiJump FortiManager vulnerability used by nation state in espionage via MSPs

ID: 6fdebb9a-2ddd-5763-aa59-ab99b1be98e9

STIX ID: report--6fdebb9a-2ddd-5763-aa59-ab99b1be98e9

Feed Name: DoublePulsar

Threat Score
80/100

Date Published: 2024-10-22

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

This report describes a FortiManager/FortiGate FGFM implementation flaw (CVE-2024-47575) that permits unauthorized FortiGate devices to register and trigger remote code execution on FortiManager, allowing attackers to manage downstream firewalls, steal configs/credentials, and pivot across networks; the author observed active exploitation via a honeypot and identified attacker IPs on Vultr, and recommends disabling FGFM or applying patches and not exposing FGFM to the Internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.