A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests
Published: 2024-02-09
Fortinet warns of “potentially” exploited flaw in the SSL VPN functionality of FortiOS, as government agencies warn of pre-positioning by Chinese state-sponsored threat actors in U.S. critical infrastructure through exploitation of known vulnerabilities
https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.html
https://securelist.com/strikeshark-campaign/120326/
https://www.infosecurity-magazine.com/news/operation-escaneo-cloudsek-latam/
https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscape/
https://www.securityweek.com/fortinet-patches-high-severity-vulnerabilities/
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://securelist.com/malware-report-q2-2025-pc-iot-statistics/117421/
https://cybelangel.com/blog/qilin-ransomware-tactics-attack/
https://www.infosecurity-magazine.com/news/automation-vulnerability/
https://www.hipaajournal.com/qilin-ransomware-group-exploiting-critical-fortinet-flaws/
https://thehackernews.com/2025/06/former-black-basta-members-use.html
https://www.securityweek.com/threat-actor-allegedly-selling-fortinet-firewall-zero-day-exploit/
https://www.darkreading.com/vulnerabilities-threats/fortinet-zero-day-arbitrary-code-execution
https://thehackernews.com/2025/04/fortinet-warns-attackers-retain.html
https://github.com/jkhda456/quickCVE
https://github.com/belky-me/vamp-cve-oracle
https://github.com/Vampsecure-Labs/vamp-cve-oracle
https://github.com/belky-me/vamp-forticheck
https://github.com/Vampsecure-Labs/vamp-forticheck
https://github.com/eavil666/cve-poc-mapper
https://github.com/godly-raam/CVE-Research-Portfolio
https://github.com/ykrishhh/cve-pocs
https://github.com/Sxmpl3/CVE-2024-21762-Safe-Check
https://github.com/ericrihm/edge-security-ground-truth
https://github.com/sreenidhi-n/socrates
https://github.com/Arshdeep030/CVE-Exploitation-Intelligence
https://github.com/user70616E6461/phantom-intel
https://github.com/vanshkamra12/CyberThreat-Intel-LLM
https://github.com/kholcomb/threatbridge
https://github.com/RosieDomenech/cve-threat-profiler
https://github.com/Naim-ch/cve-enrichment-api
https://github.com/Naim-ch/CVE-Enrichment-API
https://github.com/J3ff-R3y/network-scanner-cmdb
https://github.com/badchars/cve-mcp
https://github.com/Kalyan-Adhikari/CVE-Checker-Local
https://github.com/Leegreen305/CVE-Threat-Intelligence-Tracker
https://github.com/yanitedhacker/cve-threat-radar
https://github.com/nikjohn7/VulnPulse
https://github.com/0x13-ByteZer0/CVE-2024-21762
https://github.com/Kimiya00/security-threat-analyzer
https://github.com/Ereline/CVE-Search
https://github.com/Disseminator/Poc_CVEs
https://github.com/vorotilovaawex/CVE-2024-21762_POC
https://github.com/r4p3c4/CVE-2024-21762-Exploit-PoC-Fortinet-SSL-VPN-Check
https://github.com/cleverg0d/CVE-2024-21762-Checker
https://github.com/tr1pl3ight/CVE-2024-21762-POC
https://github.com/Instructor-Team8/CVE-2024-20291-POC
https://github.com/BetterCzz/CVE-2024-20291-POC
https://github.com/greandfather/CVE-2024-20291-POC
https://github.com/BishopFox/cve-2024-21762-check
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21762
Published: 2024-02-09
Updated: 2026-08-04
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.84285
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest