CVE-2023-27997Active Exploitation(fortinet / fortigate_6000)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet fortigate_6000 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, version 1.2 all versions, version 1.1 all versions SSL-VPN may allow a remote attacker to execute arbitrary code or commands via specifically crafted requests.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-07-04. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-122CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortigate_6000
  • fortigate_7000
  • fortios
  • fortiproxy

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-04-06); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
fortigate_6000fortigate_7000fortiosfortiproxy

12 versions affected across 4 products

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-04-06: 1Mentions · 2026-04-21: 1Mentions · 2026-07-28: 1Mentions · 2026-08-03: 1Mentions · 2026-09-18: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-07-28: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-08-03: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-21: 1Technical Details · 2026-07-28: 1Technical Details · 2026-08-03: 1Technical Details · 2026-09-18: 104-0604-2107-2808-0309-18
Signal classification4 categories
Active Exploitation
240.0%
Patch
120.0%
General
120.0%
Disclosure
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-061
Active Exploitation1
2026-04-211
Patch1
2026-07-281
Active Exploitation1
2026-08-031
General1
2026-09-181
Disclosure1
Full discourse5 posts
  • nksistemas@nksistemas
    Active Exploitation

    Alerta Crítica: Explotación Activa de Vulnerabilidad RCE en Fortinet FortiOS SSL VPN (CVE-2023-27997) https://nksistemas.com/alerta-critica-explotacion-activa-de-vulnerabilidad-rce-en-fortinet-fortios-ssl-vpn-cve-2023-27997/

    Post summary

    The alert announces that CVE‑2023‑27997, a remote code execution flaw in Fortinet FortiOS SSL VPN, is being actively exploited in the wild.

    02001172
    6.2K followersView on X
  • Forengi, The Grand Nagus zek@Elvismen
    Disclosure

    @loquepasahora @josepeguero @PoliciaRD y con fallas críticas con CVSS 9.8 como CVE-2024-21762 y CVE-2023-27997, los roban sin tocar la CLI. Palo Alto y Check Point dominan en inspección real, y si buscas control estricto de paquetes, la CLI y arquitecturas hardened sin GUI de adorno siempre le darán patadas.

    Post summary

    The tweet references two critical CVEs (CVE-2024-21762, CVE-2023-27997) with CVSS 9.8 and discusses their impact on Palo Alto/Check Point products, but provides no PoC, exploit tool, patch, or confirmed active exploitation report — functioning primarily as a vulnerability disclosure/opinion post.

    0000039
    86 followersView on X
  • 리슈@lisuewolf
    General

    SSL VPN 취약점 문제 때문에 포티넷에서 SSL VPN을 신규 펌웨어에서는 생성 자체를 못하게 막아버렸는데 이거 때문에 공부할게 많다... CVE-2023-27997 CVE-2024-21762 같은 버퍼 오버플로우 공격이랑 RCE 공격 같은 것도 공부해야하네... 공부하면서도 이걸 왜 우리가 공부하지... 싶음....

    Post summary

    The text lists two CVEs, notes buffer overflow and RCE as related attacks, mentions Fortinet’s new firmware disabling SSL VPN to mitigate a vulnerability, and expresses intent to study the problems.

    00000135
    518 followersView on X
  • Grok@grok
    Patch

    **Here's the thorough list of major Fortinet RCE vulns (2021-Apr 2026), focused on critical/unauth ones in perimeter products. EIT = exploited in the wild (CISA KEV + vendor reports).** - **2022**: CVE-2022-42475 (FortiOS SSL VPN RCE, EIT by China actors) - **2023**: CVE-2023-27997 (FortiGate VPN heap overflow RCE, EIT); CVE-2023-33308 (FortiOS/FortiProxy buffer overflow RCE) - **2024**: CVE-2024-21762 (FortiOS SSLVPN RCE, EIT); CVE-2024-23113 (FortiOS/FortiProxy RCE, EIT) - **2025**: CVE-2025-25257 (FortiWeb pre-auth SQLi→RCE, EIT); CVE-2025-32756 (multi-product buffer overflow RCE, EIT); CVE-2025-58034 (FortiWeb cmd injection RCE, EIT) - **2026**: CVE-2026-21643 (FortiClient EMS SQLi RCE, EIT); CVE-2026-35616 (FortiClient EMS unauth RCE, EIT); CVE-2026-39808/39813 (FortiSandbox unauth RCE) Patches released for all; frequency in exposed devices drives the risk.

    Post summary

    The post catalogs Fortinet RCE vulnerabilities, notes their exploitation status, and highlights that patches have been released for all affected products.

    00000152
    8.7M followersView on X
  • The Circuitry@thecircuitry_
    Active Exploitation

    CISA orders feds: Patch exploited Fortinet EMS flaw (CVE-2023-27997) by Friday or isolate. Actively hacked in wild—9.6 CVSS remote code exec. Enterprise wake-up call. https://thecircuitry.to/article/cisa-sets-friday-patch-deadline-for-exploited-fortinet-flaw-mnndtp6p

    Post summary

    CISA issues a patch deadline for Fortinet EMS flaw CVE-2023-27997 due to active exploitation in the wild, citing a 9.6 CVSS remote code execution risk.

    0000048
    2 followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
HWfortinetfortigate_6000---
HWfortinetfortigate_7000---
OSfortinetfortios---
OSfortinetfortios6.0.10--
OSfortinetfortios6.2.4--
OSfortinetfortios6.2.6--
OSfortinetfortios6.2.7--
OSfortinetfortios6.4.10--
OSfortinetfortios6.4.12--
OSfortinetfortios6.4.2--
OSfortinetfortios6.4.6--
OSfortinetfortios6.4.8--
OSfortinetfortios7.0.10--
OSfortinetfortios7.0.5--
Appfortinetfortiproxy---

Explore more