logo

Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active Exploitation

ID: 104f0b1b-7128-5353-92da-254878c5acbf

STIX ID: report--104f0b1b-7128-5353-92da-254878c5acbf

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-02-09

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Fortinet disclosed CVE-2024-21762, a critical (CVSS 9.6) out-of-bounds write in FortiOS SSL VPN enabling unauthenticated remote code execution; CISA confirmed active exploitation and added it to its Known Exploited Vulnerabilities catalog, and Fortinet has published patches and mitigation guidance across multiple affected releases. The report also contextualizes this zero-day amid ongoing exploitation of Fortinet flaws by state-linked actors (including references to Volt Typhoon) targeting critical infrastructure, underscoring urgent patching and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.