logo

Fortinet Zero-Day CVE-2024-55591: Super-Admin Risk

ID: 41ba07e8-0dd2-5020-b162-6d3a4d238a49

STIX ID: report--41ba07e8-0dd2-5020-b162-6d3a4d238a49

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2026-03-26

Date Updated: 2026-07-17

...
...

Fortinet disclosed CVE-2024-55591, a critical authentication-bypass in FortiOS and FortiProxy (CVSSv3 9.6) exploited via the Node.js WebSocket module; attackers are observed gaining super-admin access, creating administrative/VPN accounts, and using SSL VPN to access internal networks. Fortinet lists affected versions, IoCs (suspicious IPs and log entries), and urgent mitigation steps including upgrading to fixed versions and tightening administrative access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.