CVE-2024-47575Active Exploitation(fortinet / fortimanager)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch fortinet fortimanager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.12, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-11-13. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-306

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortimanager
  • fortimanager_cloud

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 9 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-10-05); latest day: 1
  • 11 total mentions across 9 days

Affected systems

Vendors
Products
fortimanagerfortimanager_cloud

1 version affected across 2 products

Deep dive

Activity timeline11 mentions / 9d
01223Mentions · 2026-01-29: 1Mentions · 2026-04-05: 1Mentions · 2026-04-06: 1Mentions · 2026-06-17: 1Mentions · 2026-07-03: 1Mentions · 2026-09-09: 1Mentions · 2026-09-28: 1Mentions · 2026-10-05: 3Mentions · 2026-10-09: 1PoC Mentioned / Linked · 2026-04-05: 1PoC Mentioned / Linked · 2026-09-09: 1Exploit Tool / Code · 2026-09-09: 1Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-06-17: 1Active Exploitation · 2026-07-03: 1Active Exploitation · 2026-09-09: 1Active Exploitation · 2026-09-28: 1Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-04-05: 1Patch / Workaround · 2026-04-06: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-01-29: 1Technical Details · 2026-04-05: 1Technical Details · 2026-04-06: 1Technical Details · 2026-09-09: 1Technical Details · 2026-09-28: 101-2904-0504-0606-1707-0309-0909-2810-0510-09
Signal classification3 categories
Active Exploitation
571.4%
Disclosure
114.3%
Patch
114.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-01-291
Active Exploitation1
2026-04-051
Disclosure1
2026-04-061
Active Exploitation1
2026-06-171
Active Exploitation1
2026-07-031
Patch1
2026-09-091
Active Exploitation1
2026-09-281
Active Exploitation1
Full discourse11 posts
  • Bhavesh Verma@xbhaveshverma

    CVEs Explainer #13 CVE-2024-47575 (FortiManager Missing Authentication) A critical missing authentication flaw in FortiManager's fgfmd daemon (CVSS 9.8) allowed remote attackers to execute arbitrary commands. Actively exploited as a zero-day, it enabled attackers to compromise the central management plane for Fortinet firewalls, potentially granting control over an organization's entire network perimeter. Management infrastructure is a high-value target.

    0101086
    158 followersView on X
  • SHELLCODE@sh3ll_c0d3

    💥 FortiJump Zero-Day (CVE-2024-47575, CVSS 9.8): Remote attackers exploit FortiManager port 541 to harvest global firewall configs. Read Blog: https://sh3llc0d3.com/blog/fortijump-dissecting-the-fortinet-fortimanager-cve-2024-47575-zero-day/ #sh3llc0d3 #shellcode #Hacktober #ZeroDay

    10001107
    117 followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #HighCompleteness CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT | 09-09-2026 Source: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/ Key details below ↓ 🧑‍💻Actors/Campaigns: Fortibleed Lynx_ransomware 💀Threats: Pivotc2, Portscan_tool, Credential_harvesting_technique, Proxychains_tool, Ldapdomaindump_tool, Obfs4proxy_tool, Passthehash_technique, Process_injection_technique, 🎯Victims: Fortigate firewalls, United states, Chile, Colombia, United kingdom 🌐Geo: United states, United kingdom, Colombia, Chile 🔓CVEs: CVE-2024-47575 \[[Vulners](https://vulners.com/cve/CVE-2024-47575)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - fortinet fortimanager (<6.2.13, <6.4.15, <7.0.13, <7.2.8, <7.4.5) - fortinet fortimanager_cloud (le6.4.7, <7.0.13, <7.2.8, <7.4.5) CVE-2024-26304 \[[Vulners](https://vulners.com/cve/CVE-2024-26304)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown CVE-2026-35273 \[[Vulners](https://vulners.com/cve/CVE-2026-35273)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - oracle peoplesoft_enterprise_peopletools (8.61, 8.62) CVE-2025-25249 \[[Vulners](https://vulners.com/cve/CVE-2025-25249)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - fortinet fortios (<6.4.17, <7.0.18, <7.2.12, <7.4.9, <7.6.4) 📚TTPs: ⚔️Tactics: 8 🛠️Technics: 26 🧨IOCs: - Url: 1 - File: 10 - IP: 7 - Hash: 12 💽Software: FortiGate, Node.js, busybox, Active Directory, SoftPerfect Network Scanner, Google Chrome, Chrome, Microsoft Edge, Microsoft Exchange, Linux, ... 📲Wallets: wassabi 🔢Algorithms: cbc, sha256, aes, xor, base64, aes-128-gcm, aes-256-cbc 🗂️Win API: VirtualAllocEx, WriteProcessMemory, OpenProcess 📜Programming Languages: rust, javascript, cpython, python, powershell 💻Platforms: arm #threatreport: CVE-2025-25249 is a critical heap-based buffer overflow in the `cw_acd` daemon used by FortiOS and FortiSwitchManager to process CAPWAP traffic on UDP port 5246. The vulnerability permits remote, unauthenticated code execution through specially crafted requests. A recovered exploit, `fortirun.bin`, targets vulnerable FortiGate and FortiAP devices, fingerprints supported firmware, performs heap grooming with malicious CAPWAP Add Station messages, corrupts allocator metadata, and hijacks control flow using an ARM64 ROP gadget. It then invokes the native Node.js runtime to establish a reverse shell. The attack chain delivers a JavaScript stager that downloads an encrypted second-stage payload, Base64-decodes and XOR-decrypts it using the key `pivot`, writes it to `/tmp/.i.js`, and executes it in the background. The payload, PivotC2, is a Node.js remote access trojan designed for FortiGate appliances. It maintains an outbound TLS connection to its command-and-control server using a multiplexed binary protocol with channel support for shell access, command execution, file operations, port forwarding, and proxy services. PivotC2 supports interactive shells, file upload and download, SOCKS5 and HTTP tunneling, local and remote port forwarding, network interface and process discovery, DNS resolution, CIDR-based port scanning, and cleanup of infection artifacts. It also harvests FortiGate configuration files, including VDOM data and `fsv_sync.dat`, then decrypts stored secrets. Recovered credentials may include VPN pre-shared keys, SSL-VPN accounts, wireless keys, LDAP credentials, and administrator passwords. An automatic mode performs configuration harvesting, credential decryption, internal network extraction, and scans of discovered and predefined private ranges without operator intervention. The campaign’s files contained more than 30,000 target IP addresses and 178 confirmed infected sessions, concentrated primarily in the United States, Chile, Colombia, and the United Kingdom. Two US organizations experienced deeper intrusions involving internal tunneling, host discovery, browser credential theft, lateral movement, and data exfiltration. The activity is assessed as a Russian-speaking, financially motivated cybercrime operation and has been active since at least July 2026.

    Post summary

    The report details a heap-based buffer overflow in FortiOS/FortiSwitch Manager that is actively exploited in the wild, with a described exploit chain, PivotC2 RAT, and documented infection counts across several countries.

    00020247
    829 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 Critical FortiManager Zero-Day (#CVE-2024-47575): Unauthenticated RCE Exploit Exposes Enterprise Networks—Patch Now! + Video https://undercodetesting.com/critical-fortimanager-zero-day-cve-2024-47575-unauthenticated-rce-exploit-exposes-enterprise-networks-patch-now-video/ Educational Purposes!

    Post summary

    The tweet announces the discovery of a critical FortiManager zero‑day (CVE‑2024‑47575), highlights its unauthenticated RCE nature, links to a video likely containing a PoC, and urges immediate patching.

    1000099
    442 followersView on X
  • Grok@grok
    Active Exploitation

    Here's a list of some notable exploited Fortinet auth bypass CVEs from 2021-2026, based on security reports (e.g., CISA KEV, FortiGuard): - CVE-2022-40684 (2022): Auth bypass in FortiOS via crafted headers; exploited for unauthorized access in govt/org networks. - CVE-2023-36634 (2023): FortiSandbox auth bypass; used in targeted attacks. - CVE-2024-47575 (2024): FortiManager missing auth; actively exploited, leading to data exfil in thousands of devices. - CVE-2025-59718 (2025): FortiCloud SSO bypass; exploited for cross-tenant access. - CVE-2026-24858 (2026): FortiOS SSO bypass; ongoing exploitation per CISA. Impacts affected orgs globally, but "hundreds of millions" of individuals is hard to verify—estimates vary by breach scope. Patch promptly.

    Post summary

    The post catalogs several Fortinet authentication bypass CVEs that have been actively exploited worldwide, urging prompt patching.

    00010165
    8.1M followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers exploiting zero-days CVE-2024-8068 (NetScaler) and CVE-2024-47575 (FortiMail) to establish persistent access across hybrid cloud environments. Custom backdoors enabled lateral movement targeting telecom and government organizations. Runtime segmentation could help contain such post-compromise pivoting. #ZeroDay #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/netscaler-fortimail-zero-days-killsec-ransomware-arrests-2026

    0000043
    2.0K followersView on X
  • SHELLCODE@sh3ll_c0d3

    🚨 #Hacktober Intel: State-sponsored cluster UNC5820 weaponized FortiManager zero-day CVE-2024-47575 No disk persistence needed—just pure blueprint theft. Read our deep dive: 🔗 https://sh3llc0d3.com/blog/unc5820-espionage-nexus-weaponizing-fortinet-fortimanager-zero-day-cve-2024-47575-to-exfiltrate-global-enterprise-firewall-topologies/ #CyberSecurity #InfoSec #ZeroDay #sh3llc0d3

    0000046
    117 followersView on X
  • CyberTools - Enterprise ⚙️ Expertise@CyberToolsHQ
    Active Exploitation

    We added #Fortinet FortiManager missing authentication vulnerability CVE-2024-47575 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q &amp; apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/HuBvRYvRh0

    Post summary

    The post notes that CVE-2024-47575 (Fortinet FortiManager missing authentication) has been added to CISA's Known Exploited Vulnerabilities catalog, signaling active exploitation, and advises applying mitigations.

    00000247
    13.7K followersView on X
  • PatchDayAlert@patchdayalert
    Patch

    Patching CVE-2024-47575 in FortiManager stops new attacks. But if attackers already got in, they have your FortiGate configs and password hashes. The patch is step one. Here's what comes next. https://patchdayalert.com/blog/fortimanager-cve-2024-47575-fortijump-patch-is-step-one/?utm_source=x&utm_medium=social&utm_campaign=blog-tease&utm_content=fortimanager-cve-2024-47575-fortijump-patch-is-step-one

    Post summary

    Fortinet advises that patching CVE‑2024‑47575 on FortiManager will stop new attacks. If attackers had already exploited the vulnerability, additional remediation steps are needed.

    0000051
    76 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Mandiant reported that threat cluster UNC5820 has been mass-exploiting Fortinet FortiManager flaw CVE-2024-47575, compromising over 50 appliances and stealing configuration data since 27 June 2024. https://threatcluster.io/cluster/mass-exploitation-of-fortimanager-vulnerability-cve-2024-475-a5d1c907

    Post summary

    Mandiant reports that threat cluster UNC5820 has been mass‑exploiting FortiManager CVE‑2024‑47575, compromising more than 50 devices and exfiltrating configuration data since 27 June 2024.

    0000077
    356 followersView on X
  • The Circuitry@thecircuitry_
    Active Exploitation

    CISA gives feds until Friday to patch actively exploited Fortinet EMS flaw (CVE-2024-47575, CVSS 9.6). Zero-click RCE hits endpoint managers — enterprise admins, check your exposures now. https://thecircuitry.to/article/cisa-sets-friday-deadline-for-fortinet-ems-patch-mnnf0632

    Post summary

    CISA warns that Fortinet EMS has an actively exploited zero‑click RCE (CVE‑2024‑47575, CVSS 9.6) and urges federal agencies to patch by Friday.

    0000056
    2 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortimanager---
Appfortinetfortimanager7.6.0--
Appfortinetfortimanager_cloud---

Explore more