Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch fortinet fim-7901e systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
In the Volt Typhoon campaign, Chinese state-sponsored actors likely gained initial access by exploiting CVE-2022-42475 in an unpatched FortiGate 300D perimeter firewall. The device installed to protect the perimeter became the path through it. Partner content with @OPSWAT. #opswat_ics
Post summary
The post reports that Chinese state-sponsored actors exploited CVE-2022-42475 on unpatched FortiGate 300D firewalls as part of the Volt Typhoon campaign.
Operation Escaneo exposed: a coordinated campaign hit Mexican 🇲🇽 government, financial, and critical infrastructure targets via chained Fortinet and Ivanti exploits, leaving 1.3M+ records and Active Directory maps stolen.
Key findings:
- Initial access via CVE-2022-42475, CVE-2024-21762 (FortiOS SSL-VPN) and CVE-2023-46805, CVE-2024-21887, CVE-2025-0282 (Ivanti Connect Secure), with PoC code tuned to avoid crashing targets. Lateral movement extended to GhostCat, EternalBlue, Zerologon, and Log4Shell.
- Custom recon engine "Kimera" auto-scanned and triaged victims, feeding directly into the exploitation stage. Neo-reGeorg webshells landed first, then Chisel reverse tunnels (3,708 sessions over 13 days) and a GRE tunnel through a compromised Cisco router moved traffic below host-based detection.
- Exfil included 1.3M personal records, a 407MB Active Directory map, live-streamed SSL private keys, SAP service-account hashes, and browser-stored passwords. Attackers reached SAP and Oracle for command execution inside victim networks.
- The group was exposed by an open staging directory, a self-inflicted OPSEC failure that let CloudSEK reconstruct the full toolkit.
Hunt for GRE tunnels terminating at external IPs, Chisel TCP-over-HTTP sessions, and unexpected process execution under SAP or Oracle service accounts. Patch the listed Fortinet and Ivanti CVEs first; those are confirmed active entry points here.
#DFIR_Radar
Post summary
The write‑up documents a live attack campaign, presenting PoC code, exploitation steps, and urging immediate patching of the listed Fortinet and Ivanti CVEs.
The post simply lists five trending CVE identifiers with hashtags and a link to a dashboard, providing no additional details or actionable information.
**Here's the thorough list of major Fortinet RCE vulns (2021-Apr 2026), focused on critical/unauth ones in perimeter products. EIT = exploited in the wild (CISA KEV + vendor reports).**
- **2022**: CVE-2022-42475 (FortiOS SSL VPN RCE, EIT by China actors)
- **2023**: CVE-2023-27997 (FortiGate VPN heap overflow RCE, EIT); CVE-2023-33308 (FortiOS/FortiProxy buffer overflow RCE)
- **2024**: CVE-2024-21762 (FortiOS SSLVPN RCE, EIT); CVE-2024-23113 (FortiOS/FortiProxy RCE, EIT)
- **2025**: CVE-2025-25257 (FortiWeb pre-auth SQLi→RCE, EIT); CVE-2025-32756 (multi-product buffer overflow RCE, EIT); CVE-2025-58034 (FortiWeb cmd injection RCE, EIT)
- **2026**: CVE-2026-21643 (FortiClient EMS SQLi RCE, EIT); CVE-2026-35616 (FortiClient EMS unauth RCE, EIT); CVE-2026-39808/39813 (FortiSandbox unauth RCE)
Patches released for all; frequency in exposed devices drives the risk.
Post summary
The post catalogs major Fortinet RCE vulnerabilities from 2021‑2026, notes that each is exploited in the wild (EIT), and confirms that patches have been released for all.
🚨 [HIGH] Active exploitation detected: CVE-2022-42475
Exploit in the wild confirmed for CVE-2022-42475 (CVSS null). Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulne...
🔗 http://ctiwatch.cloud/alerts
#ZeroDay#ExploitInWild#CyberSecurity
Post summary
The message confirms in‑the‑wild exploitation of CVE‑2022‑42475, a heap‑based buffer overflow in Fortinet FortiOS SSL‑VPN, but provides no PoC, exploit code, or patch details.