CVE-2022-40684Active Exploitation(fortinet / fortios)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet fortios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-11-01. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios
  • fortiproxy
  • fortiswitchmanager

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 7 observed days

What's happening

  • Active exploitation reported across 3 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 4 classified signals
  • Peaked 4d ago at 2 mentions (2026-05-16); latest day: 1
  • 8 total mentions across 7 days

Affected systems

Vendors
Products
fortiosfortiproxyfortiswitchmanager

2 versions affected across 3 products

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-01-29: 1Mentions · 2026-04-08: 1Mentions · 2026-05-16: 2Mentions · 2026-06-12: 1Mentions · 2026-06-18: 1Mentions · 2026-07-27: 1Mentions · 2026-09-09: 1PoC Mentioned / Linked · 2026-09-09: 1Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-06-18: 1Patch / Workaround · 2026-01-29: 1Technical Details · 2026-01-29: 1Technical Details · 2026-06-12: 101-2904-0805-1606-1206-1807-2709-09
Signal classification2 categories
Active Exploitation
450.0%
General
450.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-291
Active Exploitation1
2026-04-081
Active Exploitation1
2026-05-162
General2
2026-06-121
Active Exploitation1
2026-06-181
Active Exploitation1
2026-07-271
General1
2026-09-091
General1
Full discourse8 posts
  • Aircorridor@_aircorridor
    General

    Authentication Bypass on Fortinet Fortios | CVE-2022-40684 If hackers compromise your VPN or router, your data is at risk. https://hackers-arise.com/vpn-hacking-authentication-bypass-on-fortinet-fortios/ @three_cube @DI0256 @IamSmouk @co11ateral

    Post summary

    The post references a potential authentication bypass (CVE‑2022‑40684) in FortiOS, but provides no technical details, PoC code, patch information, or evidence of active exploitation.

    07018111.7K
    14.8K followersView on X
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    Team Cymru’s tweet lists the top 25 CVEs currently being exploited, differentiated by unique source IPs over a 14‑day period, but provides no PoC, exploit code, patch info, or technical details.

    070921.2K
    5.5K followersView on X
  • Carlos Vieira@carlos_crowsec
    Active Exploitation

    Over 68,000 Exposed Firewalls. The @quimerax_intel analyzed the FortiBleed dataset and cross-referenced it with the historical Belsen Group leak associated with the exploitation of CVE-2022-40684 in Fortinet devices. By consolidating both datasets, we were able to identify not only devices exposed in the recent FortiBleed campaign, but also firewalls that have remained exposed across multiple years. Our findings revealed: • 68,732 unique IP addresses in the FortiBleed dataset (2026) • 15,469 unique IP addresses in the Belsen Group leak (2022) • 83,676 unique IP addresses in the combined dataset • 525 IP addresses appearing in both leaks These 525 devices represent the highest-risk category. They were compromised during the 2022 campaign and still appeared in exposure data collected in 2026, suggesting a potential multi-year exposure window. We also identified more than 350 (+600creds) Brazilian organizations appearing in the analyzed data. To help organizations assess their exposure, QuimeraX provides a free lookup tool that allows security and infrastructure teams to search by both public firewall IP address and domain. Check whether your organization has been affected: http://tools.quimerax.com/fortibleed

    Post summary

    The report highlights that over 68,000 firewalls were exposed to CVE-2022-40684, with 525 devices showing multi‑year exposure, and it offers a lookup tool for organizations to assess their risk.

    130931.1K
    3.2K followersView on X
  • rgacz@rgacz
    General

    Je to skoro 1,5 roku od Belsen Group leak, který zneužíval zranitelnosti CVE-2022-40684 (2022-10-18) a CVE-2019-6693 (2019-11-21). Po skoro 4 letech od této zranitelnosti stále běží tisíce zařízení na zranitelném FortiOS 7.0.0 až 7.0.6 a 7.2.0 a 7.2.1.

    Post summary

    The passage references a Belsen Group leak that exploited CVE-2022-40684 and CVE-2019-6693, noting that many devices continue to run vulnerable FortiOS versions years after the initial exploitation.

    1000052
    539 followersView on X
  • Grok@grok
    Active Exploitation

    Here's a list of some notable exploited Fortinet auth bypass CVEs from 2021-2026, based on security reports (e.g., CISA KEV, FortiGuard): - CVE-2022-40684 (2022): Auth bypass in FortiOS via crafted headers; exploited for unauthorized access in govt/org networks. - CVE-2023-36634 (2023): FortiSandbox auth bypass; used in targeted attacks. - CVE-2024-47575 (2024): FortiManager missing auth; actively exploited, leading to data exfil in thousands of devices. - CVE-2025-59718 (2025): FortiCloud SSO bypass; exploited for cross-tenant access. - CVE-2026-24858 (2026): FortiOS SSO bypass; ongoing exploitation per CISA. Impacts affected orgs globally, but "hundreds of millions" of individuals is hard to verify—estimates vary by breach scope. Patch promptly.

    Post summary

    The post lists multiple Fortinet authentication bypass CVEs that have been actively exploited in the wild, highlights that patches are available, and provides technical details on each vulnerability.

    00010165
    8.1M followersView on X
  • PatchDay Alert@patchdayalert
    Active Exploitation

    Patching CVE-2022-40684 won't save you. This Fortinet auth bypass let attackers plant admin accounts before the fix. If your FortiOS, FortiProxy, or FortiSwitchManager got hit, you need forensics, not just patches. https://patchdayalert.com/blog/fortinet-cve-2022-40684-auth-bypass-persistence/?utm_source=twitter&utm_medium=social&utm_campaign=auto-drip&utm_content=fortinet-cve-2022-40684-auth-bypass-persistence

    Post summary

    The post highlights that the Fortinet CVE-2022-40684 auth bypass has likely been used to create admin accounts, suggesting exploitation in the wild, and stresses that patching alone may not mitigate the threat.

    0000039
    52 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2022-40684 — Akamai Connected Cloud Visit -- https://cti.loginsoft.com/ip/2600:3c00::f03c:94ff:fe1a:48ff #Loginsoft #Cytellite #Cybersecurity #CVE202240684 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/LhSC4x5370

    Post summary

    The tweet merely notes detection of CVE-2022-40684 but provides no further technical, exploit, or mitigation details.

    0000047
    20 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2022-40684 — Akamai Connected Cloud Visit -- https://cti.loginsoft.com/ip/2600:3c00::f03c:94ff:fe1a:48ff #Loginsoft #Cytellite #Cybersecurity #CVE202240684 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/H32eR6opXP

    Post summary

    The tweet references detection of activity targeting CVE-2022-40684 but offers no further technical details, exploit code, or mitigation information.

    0000048
    20 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
Appfortinetfortiproxy---
Appfortinetfortiproxy7.2.0--
Appfortinetfortiswitchmanager7.0.0--
Appfortinetfortiswitchmanager7.2.0--

Explore more