CVE-2022-42475Active Exploitation(fortinet / fim-7901e)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet fim-7901e systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-01-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-197CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fim-7901e
  • fim-7904e
  • fim-7910e
  • fim-7920e

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-04-14); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
fim-7901efim-7904efim-7910efim-7920efim-7921ffim-7941ffortigate-6300ffortigate-6300f-dcfortigate-6500ffortigate-6500f-dc

1 version affected across 23 products

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-04-14: 1Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1Mentions · 2026-06-18: 1Mentions · 2026-09-04: 1PoC Mentioned / Linked · 2026-06-18: 1Exploit Tool / Code · 2026-06-18: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-09-04: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-06-18: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-21: 1Technical Details · 2026-06-18: 104-1404-2104-2206-1809-04
Signal classification2 categories
Active Exploitation
480.0%
General
120.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-141
Active Exploitation1
2026-04-211
Active Exploitation1
2026-04-221
General1
2026-06-181
Active Exploitation1
2026-09-041
Active Exploitation1
Full discourse5 posts
  • Carolina@CRudinschi
    Active Exploitation

    In the Volt Typhoon campaign, Chinese state-sponsored actors likely gained initial access by exploiting CVE-2022-42475 in an unpatched FortiGate 300D perimeter firewall. The device installed to protect the perimeter became the path through it. Partner content with @OPSWAT. #opswat_ics

    Post summary

    The post reports that Chinese state-sponsored actors exploited CVE-2022-42475 on unpatched FortiGate 300D firewalls as part of the Volt Typhoon campaign.

    20090623
    16.4K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Operation Escaneo exposed: a coordinated campaign hit Mexican 🇲🇽 government, financial, and critical infrastructure targets via chained Fortinet and Ivanti exploits, leaving 1.3M+ records and Active Directory maps stolen. Key findings: - Initial access via CVE-2022-42475, CVE-2024-21762 (FortiOS SSL-VPN) and CVE-2023-46805, CVE-2024-21887, CVE-2025-0282 (Ivanti Connect Secure), with PoC code tuned to avoid crashing targets. Lateral movement extended to GhostCat, EternalBlue, Zerologon, and Log4Shell. - Custom recon engine "Kimera" auto-scanned and triaged victims, feeding directly into the exploitation stage. Neo-reGeorg webshells landed first, then Chisel reverse tunnels (3,708 sessions over 13 days) and a GRE tunnel through a compromised Cisco router moved traffic below host-based detection. - Exfil included 1.3M personal records, a 407MB Active Directory map, live-streamed SSL private keys, SAP service-account hashes, and browser-stored passwords. Attackers reached SAP and Oracle for command execution inside victim networks. - The group was exposed by an open staging directory, a self-inflicted OPSEC failure that let CloudSEK reconstruct the full toolkit. Hunt for GRE tunnels terminating at external IPs, Chisel TCP-over-HTTP sessions, and unexpected process execution under SAP or Oracle service accounts. Patch the listed Fortinet and Ivanti CVEs first; those are confirmed active entry points here. #DFIR_Radar

    Post summary

    The write‑up documents a live attack campaign, presenting PoC code, exploitation steps, and urging immediate patching of the listed Fortinet and Ivanti CVEs.

    10021476
    1.8K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2023-33308 2 - CVE-2022-42475 3 - CVE-2026-32201 4 - CVE-2026-33827 5 - CVE-2024-3721 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVE identifiers with hashtags and a link to a dashboard, providing no additional details or actionable information.

    00020264
    1.7K followersView on X
  • Grok@grok
    Active Exploitation

    **Here's the thorough list of major Fortinet RCE vulns (2021-Apr 2026), focused on critical/unauth ones in perimeter products. EIT = exploited in the wild (CISA KEV + vendor reports).** - **2022**: CVE-2022-42475 (FortiOS SSL VPN RCE, EIT by China actors) - **2023**: CVE-2023-27997 (FortiGate VPN heap overflow RCE, EIT); CVE-2023-33308 (FortiOS/FortiProxy buffer overflow RCE) - **2024**: CVE-2024-21762 (FortiOS SSLVPN RCE, EIT); CVE-2024-23113 (FortiOS/FortiProxy RCE, EIT) - **2025**: CVE-2025-25257 (FortiWeb pre-auth SQLi→RCE, EIT); CVE-2025-32756 (multi-product buffer overflow RCE, EIT); CVE-2025-58034 (FortiWeb cmd injection RCE, EIT) - **2026**: CVE-2026-21643 (FortiClient EMS SQLi RCE, EIT); CVE-2026-35616 (FortiClient EMS unauth RCE, EIT); CVE-2026-39808/39813 (FortiSandbox unauth RCE) Patches released for all; frequency in exposed devices drives the risk.

    Post summary

    The post catalogs major Fortinet RCE vulnerabilities from 2021‑2026, notes that each is exploited in the wild (EIT), and confirms that patches have been released for all.

    00000152
    8.7M followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2022-42475 Exploit in the wild confirmed for CVE-2022-42475 (CVSS null). Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulne... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The message confirms in‑the‑wild exploitation of CVE‑2022‑42475, a heap‑based buffer overflow in Fortinet FortiOS SSL‑VPN, but provides no PoC, exploit code, or patch details.

    00000119
    5.6K followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
HWfortinetfim-7901e---
HWfortinetfim-7904e---
HWfortinetfim-7910e---
HWfortinetfim-7920e---
HWfortinetfim-7921f---
HWfortinetfim-7941f---
HWfortinetfortigate-6300f---
HWfortinetfortigate-6300f-dc---
HWfortinetfortigate-6500f---
HWfortinetfortigate-6500f-dc---
HWfortinetfortigate-6501f---
HWfortinetfortigate-6501f-dc---
HWfortinetfortigate-6601f---
HWfortinetfortigate-6601f-dc---
HWfortinetfortigate-7030e---
HWfortinetfortigate-7040e---
HWfortinetfortigate-7060e---
HWfortinetfortigate-7121f---
OSfortinetfortios---
Appfortinetfortiproxy---
HWfortinetfpm-7620e---
HWfortinetfpm-7620f---
HWfortinetfpm-7630e---

Explore more