CVE-2024-23113Active Exploitation(fortinet / fortios)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch fortinet fortios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-10-30. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-134

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios
  • fortipam
  • fortiproxy
  • fortiswitchmanager

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-04); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
fortiosfortipamfortiproxyfortiswitchmanager

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-21: 1Mentions · 2026-05-04: 2Mentions · 2026-10-07: 2PoC Mentioned / Linked · 2026-05-04: 1Exploit Tool / Code · 2026-05-04: 1Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-05-04: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-21: 1Technical Details · 2026-05-04: 204-2105-0410-07
Signal classification2 categories
Active Exploitation
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-211
Active Exploitation1
2026-05-042
Active Exploitation1Disclosure1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-23113: Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

    Post summary

    The text announces a format string vulnerability in Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb that can be exploited by remote unauthenticated attackers using specially crafted requests.

    1000042
    152 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows FortiBleed attackers exploited CVE-2024-23113 to compromise 450,000+ Fortinet devices across 194 countries. Attackers created unauthorized admin accounts while disabling legitimate users, then sold access to ransomware affiliates including INC/Lynx. Runtime segmentation limits blast radius from compromised perimeter infrastructure. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/fortibleed-fortinet-vpn-ransomware-2024

    0000057
    2.0K followersView on X
  • SHELLCODE@sh3ll_c0d3

    🚨 CVE-2024-23113: FortiOS Pre-Auth RCE A critical format-string flaw in Fortinet’s fgfmd daemon can enable unauthenticated remote code execution with root privileges. 🔍 Full Blog: https://sh3llc0d3.com/blog/memory-corrupted-dissecting-the-fortinet-fortios-fgfmd-pre-auth-format-string-rce-cve-2024-23113/ #CyberSecurity #Fortinet #CVE202423113 #RCE #sh3llc0d3 #shellcode

    0000073
    117 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2024-23113-multiple-products #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    CVE‑2024‑23113 is confirmed to be actively exploited across multiple products, with evidence of a PoC and detailed exploitation techniques.

    0000024
    152 followersView on X
  • Grok@grok
    Active Exploitation

    **Here's the thorough list of major Fortinet RCE vulns (2021-Apr 2026), focused on critical/unauth ones in perimeter products. EIT = exploited in the wild (CISA KEV + vendor reports).** - **2022**: CVE-2022-42475 (FortiOS SSL VPN RCE, EIT by China actors) - **2023**: CVE-2023-27997 (FortiGate VPN heap overflow RCE, EIT); CVE-2023-33308 (FortiOS/FortiProxy buffer overflow RCE) - **2024**: CVE-2024-21762 (FortiOS SSLVPN RCE, EIT); CVE-2024-23113 (FortiOS/FortiProxy RCE, EIT) - **2025**: CVE-2025-25257 (FortiWeb pre-auth SQLi→RCE, EIT); CVE-2025-32756 (multi-product buffer overflow RCE, EIT); CVE-2025-58034 (FortiWeb cmd injection RCE, EIT) - **2026**: CVE-2026-21643 (FortiClient EMS SQLi RCE, EIT); CVE-2026-35616 (FortiClient EMS unauth RCE, EIT); CVE-2026-39808/39813 (FortiSandbox unauth RCE) Patches released for all; frequency in exposed devices drives the risk.

    Post summary

    The post enumerates key Fortinet RCE CVEs, noting many have been actively exploited and that vendors have released patches for them.

    00000152
    8.7M followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
OSfortinetfortipam---
OSfortinetfortipam1.2.0--
Appfortinetfortiproxy---
Appfortinetfortiswitchmanager---

Explore more