CVE-2024-21762Active Exploitation(fortinet / fortios)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch fortinet fortios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-02-16. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios
  • fortiproxy

Threat summary

  • Active exploitation appears in 28 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 35 mentions across 23 observed days

What's happening

  • Active exploitation reported across 28 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 18 signals
  • Disclosure: 1 classified signal
  • Peaked 6d ago at 5 mentions (2026-09-15); latest day: 1
  • 35 total mentions across 23 days

Affected systems

Vendors
Products
fortiosfortiproxy

Deep dive

Activity timeline35 mentions / 23d
01345Mentions · 2026-02-23: 2Mentions · 2026-03-09: 1Mentions · 2026-03-10: 2Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Mentions · 2026-03-20: 2Mentions · 2026-04-21: 2Mentions · 2026-05-04: 2Mentions · 2026-05-11: 1Mentions · 2026-06-15: 1Mentions · 2026-06-18: 1Mentions · 2026-06-24: 1Mentions · 2026-07-24: 1Mentions · 2026-08-03: 1Mentions · 2026-08-04: 1Mentions · 2026-09-14: 3Mentions · 2026-09-15: 5Mentions · 2026-09-16: 1Mentions · 2026-09-17: 1Mentions · 2026-09-18: 2Mentions · 2026-09-24: 1Mentions · 2026-10-02: 1Mentions · 2026-10-05: 1PoC Mentioned / Linked · 2026-04-21: 1PoC Mentioned / Linked · 2026-06-18: 1Exploit Tool / Code · 2026-05-11: 1Exploit Tool / Code · 2026-06-18: 1Exploit Tool / Code · 2026-09-15: 1Active Exploitation · 2026-02-23: 2Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-13: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-04-21: 2Active Exploitation · 2026-05-04: 2Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-07-24: 1Active Exploitation · 2026-08-04: 1Active Exploitation · 2026-09-14: 3Active Exploitation · 2026-09-15: 5Active Exploitation · 2026-09-16: 1Active Exploitation · 2026-09-17: 1Active Exploitation · 2026-09-18: 2Active Exploitation · 2026-09-24: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-04-21: 2Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-09-14: 2Patch / Workaround · 2026-09-24: 1Technical Details · 2026-02-23: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-13: 1Technical Details · 2026-03-20: 1Technical Details · 2026-04-21: 2Technical Details · 2026-05-11: 1Technical Details · 2026-06-18: 1Technical Details · 2026-06-24: 1Technical Details · 2026-08-04: 1Technical Details · 2026-09-14: 1Technical Details · 2026-09-15: 2Technical Details · 2026-09-16: 1Technical Details · 2026-09-18: 1Technical Details · 2026-09-24: 102-2303-1003-1304-2105-1106-1807-2408-0409-1509-1709-2410-05
Signal classification5 categories
Active Exploitation
2678.8%
Patch
412.1%
Disclosure
13.0%
General
13.0%
Exploit
13.0%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-232
Active Exploitation2
2026-03-091
Active Exploitation1
2026-03-102
Active Exploitation1Disclosure1
2026-03-111
Patch1
2026-03-131
Active Exploitation1
2026-03-202
Active Exploitation1General1
2026-04-212
Patch2
2026-05-042
Active Exploitation2
2026-05-111
Exploit1
2026-06-151
Active Exploitation1
2026-06-181
Active Exploitation1
2026-06-241
Active Exploitation1
2026-07-241
Active Exploitation1
2026-08-031
Patch1
2026-08-041
Active Exploitation1
2026-09-143
Active Exploitation3
2026-09-155
Active Exploitation5
2026-09-161
Active Exploitation1
2026-09-171
Active Exploitation1
2026-09-182
Active Exploitation2
2026-09-241
Active Exploitation1
Full discourse20 posts
  • Sans Limite@SansLimit3
    Exploit

    Exposed attacker infrastructure combining #Hermes Agent, #CyberStrikeAI, #SliverC2, and multiple LLMs used for automated CVE targeting, exploit validation, Telegram-based orchestration, and post-exploitation validation workflows. Opendir: 142.171.160[.]137:8888 VULN-MONITOR: 142.171.149[.169:8001 - Real-time 1day/0day RCE tracking across 18 sources🤔 CyberStrikeAI Server: 100.81.245[.29:8080 Chain: FOFA/Shodan recon → AI-assisted target filtering → CVE/PoC enrichment → custom scanner & exploit generation → exploit validation → WebSocket/shell access → post-exploitation environment validation → Telegram-pushed operations. Targeted CVEs: CVE-2026-0300 (Palo Alto PAN-OS) CVE-2024-21762 (FortiOS/FortiProxy SSL-VPN) CVE-2026-33017 (Langflow) CVE-2026-21858 (n8n) CVE-2026-3055 (Citrix ADC/NetScaler) CVE-2026-34486 (Apache Tomcat) CVE-2026-25253 (OpenClaw/Moltbot/Clawdbot) @malwrhunterteam @500mk500 @1ZRR4H @MichalKoczwara

    Post summary

    The post describes an attacker’s automated pipeline incorporating multiple malicious tools and AI components for scanning, PoC enrichment, exploit generation, and post‑exploitation validation of several CVEs, without mentioning public PoC links, active attacks, or patches.

    837223619525.2K
    634 followersView on X
  • nksistemas@nksistemas

    Alerta Crítica: Vulnerabilidad 0-Day en FortiMail (CVE-2024-21762) Explotada Activamente https://nksistemas.com/alerta-critica-vulnerabilidad-0-day-en-fortimail-cve-2024-21762-explotada-activamente/

    01040236
    6.2K followersView on X
  • Threat Landscape@LandscapeThreat
    Active Exploitation

    Threat actors exploited FortiGate SSL-VPN vulnerability CVE-2024-21762 to compromise a Thai broadband provider and establish persistent remote access. - The intrusion reached the provider’s internal environment through the internet-facing SSL-VPN service. - Attackers deployed MeshCentral remote management agents for ongoing control. - AttackCapture identified an internet-accessible directory on a server in Thailand containing exploitation-related material, enabling discovery of the operation. MALWARE MeshCentral VULNERABILITY CVE-2024-21762 TARGET Thailand VICTIM Triple T Broadband (3BB) SECTOR ICT

    Post summary

    The text reports an in-the-wild compromise where threat actors exploited CVE-2024-21762 on FortiGate SSL-VPN to gain persistent access to a Thai broadband provider. No PoC, exploit code, or remediation information is provided.

    0003190
    98 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Operation Escaneo exposed: a coordinated campaign hit Mexican 🇲🇽 government, financial, and critical infrastructure targets via chained Fortinet and Ivanti exploits, leaving 1.3M+ records and Active Directory maps stolen. Key findings: - Initial access via CVE-2022-42475, CVE-2024-21762 (FortiOS SSL-VPN) and CVE-2023-46805, CVE-2024-21887, CVE-2025-0282 (Ivanti Connect Secure), with PoC code tuned to avoid crashing targets. Lateral movement extended to GhostCat, EternalBlue, Zerologon, and Log4Shell. - Custom recon engine "Kimera" auto-scanned and triaged victims, feeding directly into the exploitation stage. Neo-reGeorg webshells landed first, then Chisel reverse tunnels (3,708 sessions over 13 days) and a GRE tunnel through a compromised Cisco router moved traffic below host-based detection. - Exfil included 1.3M personal records, a 407MB Active Directory map, live-streamed SSL private keys, SAP service-account hashes, and browser-stored passwords. Attackers reached SAP and Oracle for command execution inside victim networks. - The group was exposed by an open staging directory, a self-inflicted OPSEC failure that let CloudSEK reconstruct the full toolkit. Hunt for GRE tunnels terminating at external IPs, Chisel TCP-over-HTTP sessions, and unexpected process execution under SAP or Oracle service accounts. Patch the listed Fortinet and Ivanti CVEs first; those are confirmed active entry points here. #DFIR_Radar

    Post summary

    Operation Escaneo demonstrates an active, coordinated exploitation campaign using multiple Fortinet and Ivanti CVEs, with PoC code and custom tools, resulting in massive data exfiltration and highlighting the urgency of patching these vulnerabilities.

    10021476
    1.8K followersView on X
  • ZeroDayFacts@ZeroDayFacts
    Active Exploitation

    🚨 CRITICAL: FortiGate SSL-VPN flaw exploited in major broadband provider intrusion Attackers reportedly compromised infrastructure linked to Thailand’s 3BB using CVE-2024-21762, a critical FortiOS vulnerability that enables unauthenticated remote code execution. The intrusion reportedly involved: 1. Initial FortiGate compromise 2. Privilege escalation 3. Credential & SSH key theft 4. Internal reconnaissance & lateral movement 5. RADIUS/database targeting 6. Persistent MeshCentral remote access 7. Anti-forensic cleanup Researchers also uncovered VPN credentials, private keys, database passwords and internal network information in an attacker-controlled staging server. #Fortinet #CVE #VPN #CyberAttack #NetworkSecurity

    Post summary

    The post reports active exploitation of CVE-2024-21762, a critical FortiOS SSL-VPN vulnerability enabling unauthenticated remote code execution, in a major broadband provider intrusion in Thailand.

    00011180
    23 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Ransomware in 2026 is fragmented, privatized, and harder to disrupt. Qilin leads with 1,062 attacks in 2025 via CVE-2024-21762 on Fortinet edges; INC Ransom abuses Restic renamed "winupdate.exe" for exfiltration. #DFIR_Radar https://t.co/q5rC0N6hMf

    Post summary

    The tweet reports that Qilin ransomware is actively exploiting CVE-2024-21762 against Fortinet edge devices, underscoring the ongoing threat of this vulnerability.

    10010183
    1.8K followersView on X
  • Wasteland@wastelandweekly
    Active Exploitation

    🚨 CRITICAL: CVE-2024-21762 — Fortinet FortiOS/FortiProxy RCE CVSS 9.8. No auth needed. Actively exploited in ransomware campaigns. CISA KEV confirmed. If you are running FortiOS 6.x–7.4.2 or FortiProxy 1.x–7.4.2, patch immediately. #CyberSecurity #Fortinet #RCE #KEV #InfoSec

    Post summary

    The post confirms CVE‑2024‑21762 as a critical RCE in Fortinet products that is actively exploited by ransomware, with CISA KEV confirmation, and urges users to apply the available patch immediately.

    1001066
    5 followersView on X
  • Ciber_Hats@Ciber_Hats
    Active Exploitation

    🚨 #Alerta: Reportan explotación masiva de la falla CVE-2024-21762 en dispositivos #FortiGate. 600 equipos ya han sido comprometidos para ejecución remota de código. #Ciberseguridad #Panama #HackingNews #Fortinet https://t.co/ttT79JIkrd

    Post summary

    The tweet reports massive exploitation of CVE-2024-21762 on FortiGate devices, with 600 units compromised and remote code execution confirmed.

    0101088
    9 followersView on X
  • ERC ciberseguridad@ERCColombia
    Active Exploitation

    🚨 #CyberAlert: Hackers explotan falla crítica CVE-2024-21762 en 600 dispositivos FortiGate. Permite ejecución remota de código y control total de infraestructuras.#Ciberseguridad #Fortinet #Fortigate https://t.co/JY1rusPCpb

    Post summary

    The tweet reports that hackers are actively exploiting CVE-2024-21762 on 600 FortiGate devices, enabling remote code execution and full infrastructure control.

    0101080
    135 followersView on X
  • CyberNexora News@CyberNexoraNews
    Active Exploitation

    ⚠️ Critical FortiGate Vulnerability Exploited Attackers reportedly exploited CVE-2024-21762 to target 3BB, with the intrusion allegedly spreading into internal systems. 🔐 #FortiGate #CyberSecurity #CVE202421762 #CyberAttack #3BB #InfoSec #NetworkSecurity #CyberNexoraNews https://t.co/23U6RwGcYZ

    Post summary

    The tweet reports active exploitation of CVE-2024-21762 against 3BB, with intrusion spreading into internal systems. No PoC, technical details, or patch information is provided; confidence is Medium due to hedging language ('reportedly,' 'allegedly').

    00010158
    29 followersView on X
  • The Daily Tech Feed@dailytechonx
    Active Exploitation

    A never-before-seen breach: attackers leveraged a critical SSL-VPN flaw (CVE-2024-21762) in FortiGate 60F to infiltrate Thailand’s 3BB broadband network. Credential theft, privilege escalation, remote access via MeshCentral—all signs of a deep, persistent compromise. If you haven’t patched, or revoked exposed certificates, your VPN setup might be next. #SSLVPN #FortiGate #CVE202421762 #3BB #CyberAttack #VPNSecurity #MeshCentral #ThreatIntel https://thedailytechfeed.com/critical-fortigate-ssl-vpn-flaw-exploited-in-broad-attack-on-thai-broadband-provider/

    Post summary

    The text reports active in-the-wild exploitation of CVE-2024-21762 against a Thai ISP, detailing post-exploitation tactics and urging immediate patching and certificate revocation.

    00010118
    732 followersView on X
  • Silent Vector@gh0st_V3ctbrv
    Active Exploitation

    Qilin's initial access playbook 👇 → phishing + spear phishing — AI-generated lures, near-impossible to spot → VPN exploitation — FortiGate CVE-2024-55591, CVE-2024-21762 → SAP NetWeaver zero-day — CVE-2025-31324 (CVSS 10.0) exploited before public disclosure → Check Point VPN — CVE-2026-50751 actively exploited this month → MSP supply chain — compromise one IT provider → push ransomware to all their clients one MSP breach in South Korea let them hit 25 financial firms in a single month. 🏦

    Post summary

    The message lists multiple CVEs and explicitly states that several of them are or have been actively exploited in real‑world attacks, highlighting the threat landscape for those vulnerabilities.

    10000116
    9.3K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-21762. Status: ✅ Confirmed exploited in the wild Date added: 2024-02-09 Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

    Post summary

    CVE-2024-21762 is confirmed to be actively exploited; vendors advise applying mitigations or discontinuing product use.

    1000045
    152 followersView on X
  • Grok@grok
    Patch

    Fortinet has patched numerous critical RCE vulns in the past 5 years across FortiOS, FortiProxy, FortiClient EMS, FortiSandbox, etc. Many were unauthenticated/high-severity and some exploited in the wild. Notable ones: - CVE-2023-33308 (FortiOS/FortiProxy, CVSS 9.8 buffer overflow) - CVE-2024-21762 (FortiOS SSL VPN RCE, wild exploitation) - CVE-2026-35616 (FortiClient EMS zero-day unauth RCE) - CVE-2026-39808 & CVE-2026-39813 (FortiSandbox unauth RCE, public PoC) Patches exist, but the frequency in perimeter products is why some avoid them.

    Post summary

    The note lists several critical Fortinet CVEs, notes available patches and even a public PoC for FortiSandbox RCEs, while highlighting that some of these vulnerabilities are being exploited in the wild.

    10000143
    8.7M followersView on X
  • Wasteland@wastelandweekly
    Disclosure

    What it is: CVE-2024-21762 is an out-of-bounds write vulnerability classified under CWE-787. It enables a remote unauthenticated attacker to execute unauthorized code or commands via specially crafted HTTP requests against the affected systems. What's vulnerable: Affected produc…

    Post summary

    The text provides a brief disclosure of CVE-2024-21762, describing it as an out-of-bounds write that can enable remote code execution via HTTP requests, but offers no evidence of PoC, exploit, active use, patch, or false-positive claim.

    1000037
    5 followersView on X
  • Wasteland@wastelandweekly
    Active Exploitation

    🚨 CVE-2024-21762 — CVE-2024-21762 FortiOS Out-of-Bound Write Vulnerability. Actively exploited in the wild. Thread 👇

    Post summary

    The post reports that CVE-2024-21762, an out-of-bounds write flaw in FortiOS, is currently being exploited in the wild. No proof of concept, exploit code, or patch details are provided.

    1000039
    5 followersView on X
  • DailyCVE@dailycve

    🔴 FortiOS, Out-of-Bounds Write, #CVE-2024-21762 (Critical) -DC-Oct2026-2724 https://dailycve.com/fortios-out-of-bounds-write-cve-2024-21762-critical-dc-oct2026-2724/

    0000013
    239 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    FortiGate SSL-VPN の脆弱性 CVE-2024-21762:タイ・ブランド 3BB への攻撃の詳細とは? https://iototsecnews.jp/2026/09/14/hackers-exploit-fortigate-ssl-vpn-vulnerability-to-attack-broadband-provider/ 通信事業者のインフラを標的とした FortiGate SSL-VPN の脆弱性 CVE-2024-21762 を悪用する侵入活動が調査で判明しました。未認証の第三者による任意コード実行/リバースシェルの起動/正規ツールを用いた永続的なバックドアの構築/内部情報の窃取/ログ消去などの悪質行為が行われ、ネットワーク内部への不法侵入や機密データの漏洩といった重大被害を引き起こします。対象製品のサポート版ファームウェアへの更新/SSL-VPN 機能の無効化/侵害の有無の調査/漏洩した各種認証情報や証明書の更新/事前のフォレンジック証拠保全などの迅速な対処が求められます。 #CVE202421762 #FortiGate #Fortinet #SSLVPN #Vulnerability

    Post summary

    The article reports active exploitation of CVE-2024-21762 against a Thai broadband provider, detailing attack impacts and recommending immediate mitigation steps such as firmware updates and disabling SSL-VPN.

    00000272
    515 followersView on X
  • 9.999@Nekodirus
    Active Exploitation

    参考になった↓ タイ通信大手、FortiGateのCVE-2024-21762 悪用でサイバー攻撃の被害か 内部サーバーへ展開、RADIUS認証情報を探索 https://rocket-boys.co.jp/security-measures-lab/thai-telecom-fortigate-cve-2024-21762-report/

    Post summary

    The post suggests a Thai telecom was compromised via exploitation of FortiGate CVE-2024-21762, with attackers moving internally and seeking RADIUS credentials; it does not mention PoC, exploit tools, or patches.

    0000070
    191 followersView on X
  • Forengi, The Grand Nagus zek@Elvismen
    Active Exploitation

    @loquepasahora @josepeguero @PoliciaRD y con fallas críticas con CVSS 9.8 como CVE-2024-21762 y CVE-2023-27997, los roban sin tocar la CLI. Palo Alto y Check Point dominan en inspección real, y si buscas control estricto de paquetes, la CLI y arquitecturas hardened sin GUI de adorno siempre le darán patadas.

    Post summary

    The tweet cites CVE-2024-21762 and CVE-2023-27997 (CVSS 9.8) and implies they are being exploited remotely without CLI access, while recommending CLI-based/hardened architectures over GUI-centric solutions.

    0000039
    86 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
Appfortinetfortiproxy---

Explore more