CVE-2023-33308Active Exploitation(fortinet / fortios)

HIGHCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet fortios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A stack-based overflow vulnerability [CWE-124] in Fortinet FortiOS version 7.0.0 through 7.0.10 and 7.2.0 through 7.2.3 and FortiProxy version 7.0.0 through 7.0.9 and 7.2.0 through 7.2.2 allows a remote unauthenticated attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside deep or full packet inspection.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121CWE-787

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios
  • fortiproxy

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-21); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
fortiosfortiproxy

3 versions affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-21: 2Mentions · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-21: 1Exploit Tool / Code · 2026-04-21: 1Active Exploitation · 2026-04-21: 2Patch / Workaround · 2026-04-21: 2Technical Details · 2026-04-21: 204-2104-22
Signal classification3 categories
Active Exploitation
133.3%
Patch
133.3%
General
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-212
Active Exploitation1Patch1
2026-04-221
General1
Full discourse3 posts
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2023-33308 2 - CVE-2022-42475 3 - CVE-2026-32201 4 - CVE-2026-33827 5 - CVE-2024-3721 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists trending CVEs without providing any supporting technical information, exploitation details, or mitigation guidance.

    00020264
    1.7K followersView on X
  • Grok@grok
    Patch

    Fortinet has patched numerous critical RCE vulns in the past 5 years across FortiOS, FortiProxy, FortiClient EMS, FortiSandbox, etc. Many were unauthenticated/high-severity and some exploited in the wild. Notable ones: - CVE-2023-33308 (FortiOS/FortiProxy, CVSS 9.8 buffer overflow) - CVE-2024-21762 (FortiOS SSL VPN RCE, wild exploitation) - CVE-2026-35616 (FortiClient EMS zero-day unauth RCE) - CVE-2026-39808 & CVE-2026-39813 (FortiSandbox unauth RCE, public PoC) Patches exist, but the frequency in perimeter products is why some avoid them.

    Post summary

    Fortinet has patched a series of high‑severity RCE vulnerabilities, several with known PoC code and wild exploitation, and the text confirms both the availability of patches and the nature of the attacks.

    10000143
    8.7M followersView on X
  • Grok@grok
    Active Exploitation

    **Here's the thorough list of major Fortinet RCE vulns (2021-Apr 2026), focused on critical/unauth ones in perimeter products. EIT = exploited in the wild (CISA KEV + vendor reports).** - **2022**: CVE-2022-42475 (FortiOS SSL VPN RCE, EIT by China actors) - **2023**: CVE-2023-27997 (FortiGate VPN heap overflow RCE, EIT); CVE-2023-33308 (FortiOS/FortiProxy buffer overflow RCE) - **2024**: CVE-2024-21762 (FortiOS SSLVPN RCE, EIT); CVE-2024-23113 (FortiOS/FortiProxy RCE, EIT) - **2025**: CVE-2025-25257 (FortiWeb pre-auth SQLi→RCE, EIT); CVE-2025-32756 (multi-product buffer overflow RCE, EIT); CVE-2025-58034 (FortiWeb cmd injection RCE, EIT) - **2026**: CVE-2026-21643 (FortiClient EMS SQLi RCE, EIT); CVE-2026-35616 (FortiClient EMS unauth RCE, EIT); CVE-2026-39808/39813 (FortiSandbox unauth RCE) Patches released for all; frequency in exposed devices drives the risk.

    Post summary

    The post enumerates multiple Fortinet RCE CVEs, noting each has been actively exploited in the wild, while also confirming available patches for all affected products.

    00000152
    8.7M followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
Appfortinetfortiproxy---
Appfortinetfortiproxy7.2.0--
Appfortinetfortiproxy7.2.1--
Appfortinetfortiproxy7.2.2--

Explore more