logo

Critical RCE vulnerabilities in FortiOS exploited in-the-wild: everything you need to know

ID: 49f71c80-8367-5f5d-9318-c4c35ae5d711

STIX ID: report--49f71c80-8367-5f5d-9318-c4c35ae5d711

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2024-02-12

Date Updated: 2026-05-01

...
...

This advisory describes two critical Fortinet vulnerabilities—CVE-2024-21762 (buffer over-read/overflow via SSL-VPN parameter validation) and CVE-2024-23113 (format-string flaw in the fgfmd daemon)—both enabling remote unauthenticated code execution; CVE-2024-21762 is reportedly exploited in the wild and added to CISA's KEV. The report lists affected FortiOS/FortiProxy/FortiPAM versions with remediation paths, recommends immediate patching (or workarounds such as disabling SSL VPN or removing FGFM access if patching is not possible), and notes Wiz telemetry estimating 8% of cloud environments have vulnerable resources and 5% have publicly exposed instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.