CVE-2024-55591Active Exploitation(fortinet / fortios)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch fortinet fortios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-01-21. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-288

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios
  • fortiproxy

Threat summary

  • Active exploitation appears in 35 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 42 mentions across 27 observed days

What's happening

  • Active exploitation reported across 35 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 13 signals
  • Technical details provided in 24 signals
  • General: 3 classified signals
  • Peaked 8d ago at 7 mentions (2026-08-12); latest day: 1
  • 42 total mentions across 27 days

Affected systems

Vendors
Products
fortiosfortiproxy

Deep dive

Activity timeline42 mentions / 27d
02457Mentions · 2026-01-29: 1Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-20: 1Mentions · 2026-03-23: 1Mentions · 2026-04-01: 1Mentions · 2026-04-02: 2Mentions · 2026-05-20: 1Mentions · 2026-05-24: 1Mentions · 2026-06-03: 1Mentions · 2026-06-15: 2Mentions · 2026-06-22: 2Mentions · 2026-06-23: 2Mentions · 2026-06-24: 1Mentions · 2026-07-10: 1Mentions · 2026-08-04: 1Mentions · 2026-08-10: 1Mentions · 2026-08-11: 3Mentions · 2026-08-12: 7Mentions · 2026-08-13: 1Mentions · 2026-08-14: 3Mentions · 2026-08-15: 1Mentions · 2026-08-18: 1Mentions · 2026-08-20: 2Mentions · 2026-09-01: 1Mentions · 2026-09-03: 1Mentions · 2026-09-05: 1PoC Mentioned / Linked · 2026-03-05: 1PoC Mentioned / Linked · 2026-08-12: 1Exploit Tool / Code · 2026-04-02: 1Exploit Tool / Code · 2026-08-11: 1Exploit Tool / Code · 2026-09-01: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-20: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-04-02: 2Active Exploitation · 2026-05-20: 1Active Exploitation · 2026-05-24: 1Active Exploitation · 2026-06-03: 1Active Exploitation · 2026-06-15: 2Active Exploitation · 2026-06-22: 2Active Exploitation · 2026-06-23: 1Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-07-10: 1Active Exploitation · 2026-08-04: 1Active Exploitation · 2026-08-11: 2Active Exploitation · 2026-08-12: 5Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-08-14: 3Active Exploitation · 2026-08-15: 1Active Exploitation · 2026-08-20: 2Active Exploitation · 2026-09-01: 1Active Exploitation · 2026-09-03: 1Active Exploitation · 2026-09-05: 1Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-06-15: 2Patch / Workaround · 2026-06-22: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-08-11: 2Patch / Workaround · 2026-08-12: 3Patch / Workaround · 2026-08-20: 2Technical Details · 2026-03-04: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-22: 2Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-07-10: 1Technical Details · 2026-08-11: 2Technical Details · 2026-08-12: 4Technical Details · 2026-08-14: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-20: 1Technical Details · 2026-09-01: 1Technical Details · 2026-09-03: 101-2903-0503-2304-0205-2406-1506-2307-1008-1008-1208-1408-1809-0109-05
Signal classification5 categories
Active Exploitation
3173.8%
Patch
614.3%
General
37.1%
Exploit
12.4%
Disclosure
12.4%
Referenced assets21 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-291
General1
2026-03-041
Active Exploitation1
2026-03-051
Active Exploitation1
2026-03-201
Active Exploitation1
2026-03-231
Active Exploitation1
2026-04-011
Active Exploitation1
2026-04-022
Active Exploitation2
2026-05-201
Patch1
2026-05-241
Active Exploitation1
2026-06-031
Active Exploitation1
2026-06-152
Active Exploitation1Patch1
2026-06-222
Active Exploitation1Patch1
2026-06-232
Active Exploitation1Patch1
2026-06-241
Active Exploitation1
2026-07-101
Active Exploitation1
2026-08-041
Active Exploitation1
2026-08-101
General1
2026-08-113
Active Exploitation2Exploit1
2026-08-127
Active Exploitation5General1Patch1
2026-08-131
Active Exploitation1
2026-08-143
Active Exploitation3
2026-08-151
Active Exploitation1
2026-08-181
Disclosure1
2026-08-202
Active Exploitation1Patch1
2026-09-011
Active Exploitation1
2026-09-031
Active Exploitation1
2026-09-051
Active Exploitation1
Full discourse20 posts
  • EcuCERT@EcuCERT_EC
    Active Exploitation

    Afiliado “hastalamuerte” reveló TTP de Gentleman y disputas internas. Explotan RDWeb, SSL VPN y CVE-2024-55591 en Fortinet para omitir autenticación y comprometer redes. Mas información: https://www.ecucert.gob.ec/wp-content/uploads/2026/03/Al-2026-015-Grupo-Ransomware-Gentlemen.pdf #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtEPN https://t.co/GrLELCllCu

    Post summary

    A group named Gentleman discloses that they are actively exploiting Fortinet’s CVE-2024-55591 to bypass authentication and infiltrate networks.

    017034113.4K
    1.9K followersView on X
  • SentinelOne@SentinelOne
    Active Exploitation

    ⚠️ BAD - U.S., U.K., and South Korean authorities jointly warned that Gunra ransomware actors are actively exploiting Fortinet FortiOS and FortiProxy flaws (CVE-2024-55591 and CVE-2025-24472) to gain initial access to critical infrastructure networks. - The Conti-derived RaaS operation uses a double extortion model exfiltrating terabytes of data before encrypting systems and has listed 51 victims since emerging in April 2025, spanning healthcare, financial services, and government sectors. - Gunra actors have been observed bypassing MFA, hijacking SSL-VPN sessions, deleting backup infrastructure at both primary and disaster recovery sites, and operating exclusively between 10 p.m. and 6 a.m. to evade detection.

    Post summary

    Authorities report that Gunra ransomware is actively exploiting Fortinet FortiOS and FortiProxy flaws (CVE-2024-55591/CVE-2025-24472) to penetrate critical infrastructure networks.

    11040690
    58.4K followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    Gunra ransomware, built on leaked Conti source code, exploits FortiOS auth-bypass flaws CVE-2024-55591 and CVE-2025-24472 to plant superuser accounts before deploying ChaCha20+RSA-4096 encryption and appending .ENCRT. #DFIR_Radar https://t.co/98DUE3D73L

    Post summary

    Gunra ransomware exploits FortiOS auth‑bypass flaws (CVE‑2024‑55591 and CVE‑2025‑24472) to establish superuser accounts before encrypting victim data with ChaCha20+RSA‑4096 and appending .ENCRT.

    10031171
    2.0K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    The Gentlemen ransomware hit 483 victims across 66 countries in under a year using infostealer credentials, AI tools, and a 90% affiliate cut. Internal chat leaks reveal their complete playbook. Key findings: • Initial access via FortiOS CVE-2024-55591, ZeroLogon, PetitPotam, and stolen OWA credentials from infostealer logs • 90% affiliate revenue split (vs typical 70-80%) targeting Tier 1-3 countries and Latin America over US 🇺🇸 targets • AI-assisted operations using "abliterated" Qwen models for coding and analyzing stolen data • Cross-referenced victims had live corporate logins in http://alerts.bar stealer index before appearing on leak sites • Copied Black Basta's leaked playbook as training manual rather than developing original TTPs Immediate actions: Treat infostealer infections as breaches requiring session revocation. Deploy hardware-backed auth to prevent cookie replay attacks that bypass MFA. #DFIR_Radar

    Post summary

    Gentlemen ransomware used FortiOS CVE‑2024‑55591, ZeroLogon, and PetitPotam to compromise 483 victims worldwide, with detailed vulnerability information and recommended mitigations.

    11021389
    1.8K followersView on X
  • EcuCERT@EcuCERT_EC
    Active Exploitation

    Campaña de Gunra ataca dispositivos Fortinet explotando CVE-2024-55591 y CVE-2025-24472 para evadir MFA, elevar privilegios y acceder a redes empresariales. Mas información: https://www.ecucert.gob.ec/wp-content/uploads/2026/08/Al-2026-040-RANSOMWARE-GUNRA-EXPLOTA-VULNERABILIDADES-CRITICAS-EN-FORTINET.pdf #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtEPN https://t.co/D2pZDm0uIB

    Post summary

    Gunra is reportedly exploiting two Fortinet vulnerabilities, CVE‑2024‑55591 and CVE‑2025‑24472, in an active campaign to bypass MFA, elevate privileges, and access enterprise networks.

    00021298
    2.1K followersView on X
  • Marekitlab@marekitlab
    Active Exploitation

    Fortinet nigdy nie zawodzi… 😅 🔴 CVE-2024-55591 — 9.8 CRITICAL 🟠 CVE-2025-24472 — 8.1 HIGH Podatności w FortiOS/FortiProxy są wykorzystywane w atakach. Warto sprawdzić wersję i aktualizacje. #Fortinet #FortiGate #CVE #CyberSecurity https://t.co/nQESAuEON8

    Post summary

    The tweet warns that two high-severity Fortinet CVEs are actively exploited in the wild and urges users to verify and update their FortiOS/FortiProxy firmware.

    01200239
    20 followersView on X
  • Decryption Digest ®@DecryptionDigst
    Active Exploitation

    483 victims. 66 countries. Full encryption in under 24 hours. The Gentlemen kill chain: - CVE-2024-55591 FortiOS bypass (no creds) - GentleKiller BYOVD kills 48 vendors at kernel level - EtherRAT C2 via Ethereum contracts IOCs: https://decryptiondigest.com/blog/gentlemen-ransomware-etherrat-gentkiller-edr-bypass #Ransomware #BYOVD

    Post summary

    The post reports an active ransomware campaign exploiting CVE‑2024‑55591 with significant global reach, but provides no PoC or exploit code.

    1001081
    32 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    GOLD SHERWOOD's "Gentlemen" RaaS hit 683 victims in under a year, with sub-24-hour dwell times, BYOVD EDR killers, and a repeatable affiliate playbook analysts can now map precisely. Key findings: - Initial access relied on stolen or brute-forced VPN credentials (CVE-2024-55591 cited in third-party reporting against FortiGate) with no MFA. Within the first hour, actors established redundant VPN sessions from multiple foreign IPs, then moved laterally via RDP to file servers and domain controllers using valid domain credentials. Privilege escalation came fast: net1 localgroup, net group "domain admins", and direct account password resets secured domain admin access before defenders could respond. - Tool staging landed in C:\PerfLogs, a low-scrutiny Windows directory. EDR killing used the custom GentleKiller suite (Watchdog, Javelin, G11 variants) plus Havoc and Xkpsm-Killer, all abusing vulnerable drivers (nogbc.sys, G11.sys, dmx.sys) via BYOVD. Windows Defender was neutered via Add-MpPreference exclusions and registry keys, and avkill.bat was pushed domain-wide via NETLOGON. - Exfiltration favored Rclone (5 of 15 incidents), with adaptive pivots to Restic and MinIO Client within a single intrusion. Ransom notes drop as README-GENTLEMEN.txt; Go-based locker binaries follow naming patterns like G_<ext>_windows_amd64.exe with --superfast/--ultrafast flags. #DFIR_Radar

    Post summary

    The post details that Golden Sherwood’s RaaS is actively exploiting vulnerabilities, including CVE‑2024‑55591 and driver‑based techniques, impacting hundreds of victims worldwide.

    10100228
    1.9K followersView on X
  • Consejo d Seguridad d Información y Ciberseguridad@CONSEJOSIAC
    Active Exploitation

    🔓 Gunra explota fallos en dispositivos Fortinet FortiOS y FortiProxy conectados a internet (CVE-2024-55591 y CVE-2025-24472) para entrar y desplegar un modelo de doble extorsión: exfiltración y cifrado de datos a la vez.

    Post summary

    The text reports that the group Gunra is actively exploiting Fortinet FortiOS/ FortiProxy vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to conduct double‑extortion attacks involving data exfiltration and encryption.

    10010150
    7.4K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Gunra ransomware, a Conti-derived RaaS now operating globally, exploits FortiOS/FortiProxy auth bypasses and VPN default creds to hit healthcare, government, critical manufacturing and more across six regions. Key findings: - Initial access via CVE-2024-55591 and CVE-2025-24472 (auth bypass in FortiOS/FortiProxy) plus default credentials on SSL-VPN appliances. Lateral movement uses Impacket over SMB and stolen session tokens. Persistence achieved by installing OpenSSH and creating backdoor VPN accounts with password-change bypass. - Credential theft via http://secretsdump.py against NTDS on domain controllers enabling pass-the-hash and pass-the-ticket. Actors also modified VDI portal files to bypass MFA and stole symmetric encryption keys from a Hiware access control server via SSH. - Gunra deletes logs and command history, operates 10 p.m. to 6 a.m., and uses IsDebuggerPresent to block analysis. The Windows encryptor uses FindFirstFileW/FindNextFileW to traverse all drives A through Z with no network indicators. - Critical decryption opportunity: Linux ELF variants as of March 2026 use a weak PRNG seeded with predictable system time. File timestamps can reconstruct encryption keys mathematically, making ransom payment unnecessary for Linux victims. Patch CVE-2024-55591 and CVE-2025-24472 immediately. For Linux victims, preserve file timestamps and attempt key reconstruction before paying. Audit VPN accounts for password-change bypass and review NTDS access logs. #DFIR_Radar

    Post summary

    The post details active exploitation of FortiOS/FortiProxy authentication bypasses by the Gunra ransomware group, outlines tools and techniques used, and provides patch and mitigation guidance.

    10010267
    1.8K followersView on X
  • Gagan Suie@gagansuie
    Disclosure

    Initial access: CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in FortiOS and FortiProxy. Plus credential exposure in internet-facing VPN gateways and SSH access control weaknesses.

    Post summary

    The text announces two authentication bypass CVEs affecting FortiOS and FortiProxy (CVE-2024-55591, CVE-2025-24472) that enable initial access, alongside related credential exposure and SSH control weaknesses.

    1000034
    195 followersView on X
  • Scripted World@Milwyn1
    Active Exploitation

    Gunra ransomware gang launched formal RaaS platform in January 2026 and is actively recruiting penetration testers and ethical hackers as initial access brokers for enterprise network access. US, South Korea agencies warn the group exploits CVE-2024-55591 and CVE-2025-24472 authentication bypass flaws in Fortinet's FortiOS and FortiProxy to gain admin access. The gang targets healthcare, financial services, government, and critical infrastructure globally using double-extortion tactics with 5-7 day deadlines before data publication. South Korean research exposed links between Gunra and North Korea's Lazarus Group suggesting shared techniques, tools, and infrastructure. The ransomware is based on leaked Conti source code with Linux variant supporting 100 parallel encryption threads and partial file encryption. CISA: "Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to US and international organizations." #Gunra #Ransomware #Fortinet #Lazarus #CISA

    Post summary

    Gunra ransomware exploits authentication bypass flaws in Fortinet products, with US and South Korean agencies reporting active use; CISA underscores the ongoing threat to critical sectors.

    00010120
    1.2K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Gunra ransomware, a Conti-based RaaS also operating as "Golden Community," is exploiting CVE-2024-55591 and CVE-2025-24472 in FortiOS/FortiProxy to hit government and critical infrastructure. #DFIR_Radar https://t.co/WBeTSTKvdr

    Post summary

    The tweet reports that the Gunra ransomware group is actively exploiting FortiOS/FortiProxy CVE-2024-55591 and CVE-2025-24472 against government and critical infrastructure.

    10000158
    1.8K followersView on X
  • Decryption Digest ®@DecryptionDigst
    Active Exploitation

    51 critical infrastructure orgs breached. Polish plant offline. Gunra ransomware exploits Fortinet CVE-2024-55591 (CVSS 9.6) -- no credentials needed. CISA AA26-222A issued. Patch FortiOS to 7.0.17 now. https://www.decryptiondigest.com/blog/gunra-ransomware-critical-infrastructure-fortinet-cve-2024-55591 #Ransomware #Fortinet

    Post summary

    The post reports active exploitation of Fortinet CVE-2024-55591 by Gunra ransomware, noting 51 breached critical infrastructure organizations and a Polish plant outage, and urges a patch to FortiOS 7.0.17.

    0001055
    29 followersView on X
  • DEFION | Ciberseguridad@defionsecurity
    Active Exploitation

    CVEs con explotación activa confirmada en junio: 🔴 CVE-2025-0282 · Ivanti VPN · RCE pre-auth (9.0) 🔴 CVE-2024-55591 · FortiOS · Auth bypass (9.8) 🟠 CVE-2025-21333 · Hyper-V · LPE (7.8) Tiempo medio de explotación desde publicación: <5 días. Nuestro equipo de ITE los tiene en el radar antes de que llegue el aviso.

    Post summary

    The post confirms active exploitation of several CVEs in June, detailing vulnerability types and CVSS scores, but offers no PoC, exploit code, or patch information.

    00010152
    868 followersView on X
  • Silent Vector@gh0st_V3ctbrv
    Active Exploitation

    Qilin's initial access playbook 👇 → phishing + spear phishing — AI-generated lures, near-impossible to spot → VPN exploitation — FortiGate CVE-2024-55591, CVE-2024-21762 → SAP NetWeaver zero-day — CVE-2025-31324 (CVSS 10.0) exploited before public disclosure → Check Point VPN — CVE-2026-50751 actively exploited this month → MSP supply chain — compromise one IT provider → push ransomware to all their clients one MSP breach in South Korea let them hit 25 financial firms in a single month. 🏦

    Post summary

    The tweet outlines Qilin’s use of phishing and VPN exploitation, noting several CVEs, with a clear claim that CVE-2026-50751 is actively exploited this month.

    10000116
    9.3K followersView on X
  • Silent Vector@gh0st_V3ctbrv
    Active Exploitation

    Context that makes this worse 👇 → FortiGate is used by governments, hospitals, banks, and enterprises globally → The Gentlemen ransomware group already has 14,700 compromised FortiGate devices on standby from earlier campaigns → FortiOS CVE-2024-55591 (auth bypass) is still unpatched in thousands of orgs harvested credentials → initial access → ransomware. That's the full kill chain. and they already have the keys. 🔑

    Post summary

    The post reports that the Gentlemen ransomware group has compromised 14,700 FortiGate devices using the unpatched CVE‑2024‑55591 authentication bypass, indicating ongoing exploitation in the wild.

    1000071
    9.3K followersView on X
  • Silent Vector@gh0st_V3ctbrv
    Active Exploitation

    Their attack chain is clean and repeatable 👇 → initial access via CVE-2024-55591 (FortiOS auth bypass) or brute-forced VPN creds → they already have 14,700 compromised FortiGate devices on standby → privilege escalation → disable Defender → clear event logs → lateral movement via RDP, PsExec, WMI, PowerShell → deploy ransomware via Active Directory Group Policy — hits every machine simultaneously → double extortion: encrypt + threaten to leak stolen data 🔐

    Post summary

    The message asserts that CVE-2024-55591 is being used to gain initial access to thousands of FortiGate devices, enabling attackers to deploy ransomware across networks. It portrays widespread, ongoing exploitation of the vulnerability.

    1000065
    9.2K followersView on X
  • isogashii@cyber_risk_sec
    Active Exploitation

    日本ランサムウェア Q1 2026の日本のランサムウェア被害は21件。The Gentlemen(6件)・Everest(4件)・Nightspire(3件)の3グループで被害全体の62%を占める。The GentlemenとNightspireはFortiGateの同一脆弱性(CVE-2024-55591)への集中攻撃が継続 https://www.ransomware.live/

    Post summary

    Ransomware groups The Gentlemen and Nightspire are continuously exploiting FortiGate CVE-2024‑55591, contributing to multiple incidents in Japan and beyond.

    00001102
    121 followersView on X
  • bigmacd@bigmacd16684
    Active Exploitation

    CVE-2024-55591 &amp; CVE-2025-24472: Creating VPN tunnels through forticloud-sync service account, then going dormant for months to avoid detection. Attack linked to Matanbuchus 3.0.

    Post summary

    The post reports that CVE-2024-55591 and CVE-2025-24472 are being actively exploited to create dormant VPN tunnels through the FortiCloud sync service account, with attacks linked to the Matanbuchus 3.0 tool.

    1000099
    7 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
Appfortinetfortiproxy---

Explore more