CVE-2025-24472Active Exploitation(fortinet / fortios)

HIGHCVSS 8.1 · HIGHCISA KEV

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch fortinet fortios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

6.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-04-08. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-288

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios
  • fortiproxy

Threat summary

  • Active exploitation appears in 16 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 20 mentions across 9 observed days

What's happening

  • Active exploitation reported across 16 signals
  • Exploit tool or code specified in 3 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • General: 2 classified signals
  • Peaked 6d ago at 6 mentions (2026-08-12); latest day: 1
  • 20 total mentions across 9 days

Affected systems

Vendors
Products
fortiosfortiproxy

Deep dive

Activity timeline20 mentions / 9d
02356Mentions · 2026-04-02: 1Mentions · 2026-08-11: 5Mentions · 2026-08-12: 6Mentions · 2026-08-13: 1Mentions · 2026-08-14: 3Mentions · 2026-08-15: 1Mentions · 2026-08-18: 1Mentions · 2026-08-20: 1Mentions · 2026-09-30: 1Exploit Tool / Code · 2026-04-02: 1Exploit Tool / Code · 2026-08-11: 2Active Exploitation · 2026-04-02: 1Active Exploitation · 2026-08-11: 5Active Exploitation · 2026-08-12: 4Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-08-14: 3Active Exploitation · 2026-08-15: 1Active Exploitation · 2026-08-20: 1Patch / Workaround · 2026-08-11: 3Patch / Workaround · 2026-08-12: 2Patch / Workaround · 2026-08-20: 1Technical Details · 2026-04-02: 1Technical Details · 2026-08-11: 3Technical Details · 2026-08-12: 1Technical Details · 2026-08-14: 2Technical Details · 2026-08-18: 104-0208-1108-1208-1308-1408-1508-1808-2009-30
Signal classification4 categories
Active Exploitation
1578.9%
General
210.5%
Exploit
15.3%
Patch
15.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-021
Active Exploitation1
2026-08-115
Active Exploitation4Exploit1
2026-08-126
Active Exploitation4General1Patch1
2026-08-131
Active Exploitation1
2026-08-143
Active Exploitation3
2026-08-151
Active Exploitation1
2026-08-181
General1
2026-08-201
Active Exploitation1
Full discourse20 posts
  • SentinelOne@SentinelOne
    Active Exploitation

    ⚠️ BAD - U.S., U.K., and South Korean authorities jointly warned that Gunra ransomware actors are actively exploiting Fortinet FortiOS and FortiProxy flaws (CVE-2024-55591 and CVE-2025-24472) to gain initial access to critical infrastructure networks. - The Conti-derived RaaS operation uses a double extortion model exfiltrating terabytes of data before encrypting systems and has listed 51 victims since emerging in April 2025, spanning healthcare, financial services, and government sectors. - Gunra actors have been observed bypassing MFA, hijacking SSL-VPN sessions, deleting backup infrastructure at both primary and disaster recovery sites, and operating exclusively between 10 p.m. and 6 a.m. to evade detection.

    Post summary

    The passage reports that Gunra ransomware operators are actively exploiting Fortinet FortiOS and FortiProxy vulnerabilities (CVE-2024-55591, CVE-2025-24472) for initial access, citing multiple victims and detailed intrusion tactics.

    11040690
    58.4K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Gunra ransomware, built on leaked Conti source code, exploits FortiOS auth-bypass flaws CVE-2024-55591 and CVE-2025-24472 to plant superuser accounts before deploying ChaCha20+RSA-4096 encryption and appending .ENCRT. #DFIR_Radar https://t.co/98DUE3D73L

    Post summary

    The post reports that Gunra ransomware actively uses two FortiOS authentication‐bypass CVEs to create superuser accounts and then encrypt victim files.

    10031171
    2.0K followersView on X
  • Jim Nitterauer 🇺🇸@JNitterauer
    Active Exploitation

    US, South Korea and allied agencies warn: Gunra ransomware is breaching critical infrastructure via Fortinet (CVE-2025-24472) and Schneider Electric (CVE-2024-5559) edge flaws, then defeating MFA at the VDI portal. Patch your edge. #ransomware #Fortinet

    Post summary

    The tweet warns that Gunra ransomware is actively exploiting edge flaws in Fortinet and Schneider Electric products, breaching critical infrastructure and bypassing MFA, and it urges users to patch.

    01021210
    8.6K followersView on X
  • EcuCERT@EcuCERT_EC
    Active Exploitation

    Campaña de Gunra ataca dispositivos Fortinet explotando CVE-2024-55591 y CVE-2025-24472 para evadir MFA, elevar privilegios y acceder a redes empresariales. Mas información: https://www.ecucert.gob.ec/wp-content/uploads/2026/08/Al-2026-040-RANSOMWARE-GUNRA-EXPLOTA-VULNERABILIDADES-CRITICAS-EN-FORTINET.pdf #PorUnEcuadorCiberseguro @Arcotel_ec @CsirtCEDIA @CsirtEPN https://t.co/D2pZDm0uIB

    Post summary

    GunRA is actively exploiting Fortinet vulnerabilities CVE-2024-55591 and CVE-2025-24472 to bypass MFA and elevate privileges, indicating real‐world attacks on corporate networks.

    00021298
    2.1K followersView on X
  • Marekitlab@marekitlab
    Active Exploitation

    Fortinet nigdy nie zawodzi… 😅 🔴 CVE-2024-55591 — 9.8 CRITICAL 🟠 CVE-2025-24472 — 8.1 HIGH Podatności w FortiOS/FortiProxy są wykorzystywane w atakach. Warto sprawdzić wersję i aktualizacje. #Fortinet #FortiGate #CVE #CyberSecurity https://t.co/nQESAuEON8

    Post summary

    The tweet alerts that Fortinet CVE‑2024‑55591 (9.8 CRITICAL) and CVE‑2025‑24472 (8.1 HIGH) are actively exploited, urging users to verify firmware versions and apply updates.

    01200239
    20 followersView on X
  • Consejo d Seguridad d Información y Ciberseguridad@CONSEJOSIAC
    Active Exploitation

    🔓 Gunra explota fallos en dispositivos Fortinet FortiOS y FortiProxy conectados a internet (CVE-2024-55591 y CVE-2025-24472) para entrar y desplegar un modelo de doble extorsión: exfiltración y cifrado de datos a la vez.

    Post summary

    Gunra is actively exploiting CVE‑2024‑55591 and CVE‑2025‑24472 in Fortinet FortiOS and FortiProxy devices, deploying a double extortion strategy that both exfiltrates and encrypts data.

    10010150
    7.4K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Gunra ransomware, a Conti-derived RaaS now operating globally, exploits FortiOS/FortiProxy auth bypasses and VPN default creds to hit healthcare, government, critical manufacturing and more across six regions. Key findings: - Initial access via CVE-2024-55591 and CVE-2025-24472 (auth bypass in FortiOS/FortiProxy) plus default credentials on SSL-VPN appliances. Lateral movement uses Impacket over SMB and stolen session tokens. Persistence achieved by installing OpenSSH and creating backdoor VPN accounts with password-change bypass. - Credential theft via http://secretsdump.py against NTDS on domain controllers enabling pass-the-hash and pass-the-ticket. Actors also modified VDI portal files to bypass MFA and stole symmetric encryption keys from a Hiware access control server via SSH. - Gunra deletes logs and command history, operates 10 p.m. to 6 a.m., and uses IsDebuggerPresent to block analysis. The Windows encryptor uses FindFirstFileW/FindNextFileW to traverse all drives A through Z with no network indicators. - Critical decryption opportunity: Linux ELF variants as of March 2026 use a weak PRNG seeded with predictable system time. File timestamps can reconstruct encryption keys mathematically, making ransom payment unnecessary for Linux victims. Patch CVE-2024-55591 and CVE-2025-24472 immediately. For Linux victims, preserve file timestamps and attempt key reconstruction before paying. Audit VPN accounts for password-change bypass and review NTDS access logs. #DFIR_Radar

    Post summary

    The report details global exploitation of FortiOS/FortiProxy auth bypass vulnerabilities by the Gunra ransomware group, providing rich operational insights and actionable patch recommendations.

    10010267
    1.8K followersView on X
  • Gagan Suie@gagansuie
    General

    Initial access: CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in FortiOS and FortiProxy. Plus credential exposure in internet-facing VPN gateways and SSH access control weaknesses.

    Post summary

    The tweet lists several authentication and credential exposure vulnerabilities in Fortinet products but does not provide any PoC, exploit, patch information, or evidence of active exploitation.

    1000034
    195 followersView on X
  • Scripted World@Milwyn1
    Active Exploitation

    Gunra ransomware gang launched formal RaaS platform in January 2026 and is actively recruiting penetration testers and ethical hackers as initial access brokers for enterprise network access. US, South Korea agencies warn the group exploits CVE-2024-55591 and CVE-2025-24472 authentication bypass flaws in Fortinet's FortiOS and FortiProxy to gain admin access. The gang targets healthcare, financial services, government, and critical infrastructure globally using double-extortion tactics with 5-7 day deadlines before data publication. South Korean research exposed links between Gunra and North Korea's Lazarus Group suggesting shared techniques, tools, and infrastructure. The ransomware is based on leaked Conti source code with Linux variant supporting 100 parallel encryption threads and partial file encryption. CISA: "Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to US and international organizations." #Gunra #Ransomware #Fortinet #Lazarus #CISA

    Post summary

    The passage announces that the Gunra ransomware group is actively exploiting authentication bypass vulnerabilities in Fortinet's FortiOS and FortiProxy (CVE-2024-55591, CVE-2025-24472) to gain admin access, with agencies highlighting this ongoing threat.

    00010120
    1.2K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Gunra ransomware, a Conti-based RaaS also operating as "Golden Community," is exploiting CVE-2024-55591 and CVE-2025-24472 in FortiOS/FortiProxy to hit government and critical infrastructure. #DFIR_Radar https://t.co/WBeTSTKvdr

    Post summary

    Gunra ransomware teams are actively exploiting CVE‑2024‑55591 and CVE‑2025‑24472 in FortiOS/FortiProxy against government and critical infrastructure, with no patch or PoC details disclosed.

    10000158
    1.8K followersView on X
  • SecureChap@SecureChap
    Exploit

    Gunra Linux ransomware bakes in weak key derivation that lets anyone with a sample pull the full Salsa20 or ChaCha20 key in seconds. Access starts with CVE-2024-5559 on Schneider Electric PowerLogic P5 and CVE-2025-24472 on FortiOS 7.2.0–7.4.4 plus FortiProxy. RaaS panel hands operators a builder and separate Linux lockers; observed jobs reached 9 TB. Lateral movement runs http://impacket-psexec.py -hashes user@target plus http://smbclient.py shares, then http://secretsdump.py -ntds NTDS.dit. Exfil pushes main.exe output to OneDrive or SharePoint, MEGA for the larger archives. MFA bypass edits VDI portal files and re-uses stolen SSL-VPN cookies by swapping the session token before the server checks. Watch for odd Impacket SMB traffic and sudden cookie reuse on Fortinet endpoints.

    Post summary

    The post details how Gunra ransomware leverages CVE‑2024‑5559 and CVE‑2025‑24472, exploiting weak key derivation and abusing widespread tools like Impacket and secretsdump, with evidence of active use and large-scale exfiltration.

    0000195
    162 followersView on X
  • bigmacd@bigmacd16684
    Active Exploitation

    CVE-2024-55591 & CVE-2025-24472: Creating VPN tunnels through forticloud-sync service account, then going dormant for months to avoid detection. Attack linked to Matanbuchus 3.0.

    Post summary

    Both CVEs are reportedly used to create dormant VPN tunnels via forticloud-sync, with the activity linked to the Matanbuchus 3.0 tool, indicating ongoing exploitation.

    1000099
    7 followersView on X
  • ♫Why♥Not♪@Python_s_

    #NØØT Security Alerts Classification: Critical CVE: CVE-2025-24472 Product: Fortinet / FortiOS and FortiProxy Summary: VulnCheck reports confirmed exploitation activity affecting Fortinet / FortiOS and FortiProxy. Evidence: Ransomware use confirmed; Active exploitation reported Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation and investigate exposed systems for evidence of exploitation or compromise. Date: 11 Feb 2025 Source: https://vulncheck.com/ #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Fortinet #FortiOSandFortiProxy #CVE_2025_24472 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    0000091
    226 followersView on X
  • Jim Johnson@jvjinfinity
    Active Exploitation

    CISA named the group hunting hospitals through Fortinet holes. Ask your IT company if CVE-2024-55591 and CVE-2025-24472 are patched. Then ask who owns the risk analysis. Those are two different jobs. Only one of them is usually in the MSP contract.

    Post summary

    CISA reports a threat group targeting hospitals via Fortinet vulnerabilities (CVE-2024-55591, CVE-2025-24472), prompting a call for patching and risk assessment.

    0000036
    58 followersView on X
  • SHORT INFO@ShortInfoNews
    Active Exploitation

    CISA, the FBI, NSA and Secret Service warn that Gunra ransomware affiliates are actively exploiting unpatched Fortinet FortiOS and FortiProxy flaws CVE-2024-55591 and CVE-2025-24472 to break into healthcare, financial and government networks worldwide. https://t.co/wtPvvZIiQp

    Post summary

    CISA and other U.S. agencies warn that Gunra ransomware affiliates are actively exploiting two Fortinet CVEs (CVE-2024-55591, CVE-2025-24472) to breach healthcare, financial, and government networks worldwide.

    0000068
    157 followersView on X
  • 🄿 🅁 🄾 🄻 🄸 🅇 🄰 🄻 🄸 🄰 🅂 ™@prolixalias
    General

    https://nvd.nist.gov/vuln/detail/CVE-2025-24472

    Post summary

    A simple reference to the NVD page for CVE-2025-24472, lacking additional context or details.

    0000024
    69 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Gunra ransomware actors exploited CVE-2024-55591 and CVE-2025-24472 to bypass MFA on Fortinet appliances, then compromised identity infrastructure for lateral movement. Runtime segmentation helps contain post-compromise activity when perimeter defenses fail. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/gunra-ransomware-exploits-fortinet-vulnerabilities-bypasses-mfa-2026

    Post summary

    The report confirms that Gunra ransomware actively exploited two Fortinet CVEs to bypass MFA and facilitate lateral movement, with a link to a full analysis.

    0000086
    1.9K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Gunra ransomware exploited critical Fortinet authentication bypass flaws (CVE-2024-55591, CVE-2025-24472) to escalate to super-admin privileges and move laterally across government networks. Runtime segmentation helps contain post-compromise activity when perimeter defenses fail. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/us-and-south-korea-warn-of-gunra-ransomware-targeting-govt-agencies-2026

    Post summary

    The post reports that the Gunra ransomware group used two Fortinet authentication bypass CVEs to gain super‑admin rights and move laterally in government networks, highlighting real‑world exploitation of these vulnerabilities.

    0000086
    1.9K followersView on X
  • SecEngCyGy@snypet86
    Patch

    Joint CSA: Gunra ransomware (CISA/FBI/NSA + allies). RaaS double-extortion on gov and critical infrastructure. Edge: FortiOS/FortiProxy CVE-2024-55591 / CVE-2025-24472. Patch exposed VPN/edge. Segment. Test offline immutable backups. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a

    Post summary

    The post highlights exposure of FortiOS/FortiProxy via CVE-2024-55591 and CVE-2025-24472 and calls attention to the need for patches, pointing to a CISA advisory for remediation.

    0000079
    24 followersView on X
  • Techsico IT@Techsico_IT
    Active Exploitation

    FortiGate admins: CISA says Gunra is exploiting CVE-2024-55591 and CVE-2025-24472 to bypass MFA and steal data. PATCH. Review admin accounts, VPN logs, and configs now. https://t.co/AiSVOb4rJB

    Post summary

    The tweet reports that CISA confirms Gunra is actively exploiting CVE-2024-55591 and CVE-2025-24472 to bypass MFA and steal data, and urges FortiGate administrators to apply patches and audit configurations.

    0000053
    7 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
Appfortinetfortiproxy---

Explore more