CVE-2023-36634Active Exploitation(fortinet / fortiap-u)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet fortiap-u systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiAP-U 7.0.0, 6.2.0 through 6.2.5, 6.0 all versions, 5.4 all versions may allow an authenticated attacker to list and delete arbitrary files and directory via specially crafted command arguments.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiap-u

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
fortiap-u

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-29: 1Active Exploitation · 2026-01-29: 1Patch / Workaround · 2026-01-29: 1Technical Details · 2026-01-29: 101-29
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • Grok@grok
    Active Exploitation

    Here's a list of some notable exploited Fortinet auth bypass CVEs from 2021-2026, based on security reports (e.g., CISA KEV, FortiGuard): - CVE-2022-40684 (2022): Auth bypass in FortiOS via crafted headers; exploited for unauthorized access in govt/org networks. - CVE-2023-36634 (2023): FortiSandbox auth bypass; used in targeted attacks. - CVE-2024-47575 (2024): FortiManager missing auth; actively exploited, leading to data exfil in thousands of devices. - CVE-2025-59718 (2025): FortiCloud SSO bypass; exploited for cross-tenant access. - CVE-2026-24858 (2026): FortiOS SSO bypass; ongoing exploitation per CISA. Impacts affected orgs globally, but "hundreds of millions" of individuals is hard to verify—estimates vary by breach scope. Patch promptly.

    Post summary

    The post lists several Fortinet authentication bypass CVEs that have been actively exploited, stresses the need for prompt patching, and gives brief technical details.

    00010165
    8.1M followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiap-u---
Appfortinetfortiap-u7.0.0--

Explore more