>> All posts

CVE-2024-21762: Fortinet FortiOS SSL VPN remote code execution, actively exploited

The short version: Fortinet's FortiOS and FortiProxy SSL VPN have an out-of-bounds write flaw (CVE-2024-21762) that lets an unauthenticated attacker run code on the appliance — no login required. It's confirmed exploited in the wild and in CISA's Known Exploited Vulnerabilities catalog. The fix has been out since early 2024, so if you still run an affected build with SSL VPN enabled, you're exposed to something attackers already know how to use. Steady hands — but if this is you, patch today.

At a glance

FactDetail
Our severity takeCritical — in practice and on paper
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS83.4% · 99.6th percentile (2026-07-16)
In CISA KEV?Yes — remediation was due 2024-02-16 (BOD 22-01)
Known exploited?Yes — confirmed exploited in the wild
Vulnerability typeCWE-787 out-of-bounds write → unauthenticated remote code execution
Requires authenticated session?No — pre-authentication, over the SSL VPN interface
AffectedFortiOS 6.0.0–7.4.2 and FortiProxy 1.0.0–7.4.2 (SSL VPN enabled)
Fixed inFortiOS 7.4.3 / 7.2.7 / 7.0.14 / 6.4.15 / 6.2.16 · FortiProxy 7.4.3 / 7.2.9 / 7.0.15 / 2.0.14

What you need to know

CVE-2024-21762 is an out-of-bounds write in the FortiOS SSL VPN. By sending specially crafted HTTP requests to the VPN interface, a remote attacker with no credentials can corrupt memory and execute arbitrary code on the appliance.

The device this lives on is the problem. A FortiGate SSL VPN sits at the edge of your network and is, by design, reachable from the internet — it's how remote staff get in. Code execution there doesn't compromise one host; it hands an attacker a foothold on the device that brokers access into everything behind it.

Two things put this above a routine "Critical":

  • It's pre-authentication on an internet-facing appliance. No stolen password, no phishing, no chain required — just reachability.
  • It's already exploited. Fortinet flagged potential in-the-wild exploitation at disclosure, and CISA added it to KEV. The theoretical is operational.

How serious we see it

Critical — and here the base score and our take agree.

There's no gap to explain: NVD scores it 9.8, it's unauthenticated network-reachable code execution, and it's confirmed exploited. When those line up on a remote-access appliance, it belongs at the top of the queue.

The reassuring part is that it's bounded and fixable. It affects specific FortiOS and FortiProxy branches, fixes have shipped for every supported branch, and you can tell quickly whether an affected build is exposed. The uncomfortable part is the calendar: this fix has been available since February 2024, so "we'll get to it" has quietly become "we've been exposed for a long time."

Recommendations

Straight from Fortinet's advisory (FG-IR-24-015) and CISA:

  1. Patch now. Upgrade to a fixed build for your branch — FortiOS 7.4.3 / 7.2.7 / 7.0.14 / 6.4.15 / 6.2.16 or later, FortiProxy 7.4.3 / 7.2.9 / 7.0.15 / 2.0.14 or later. Confirm the exact target for your deployed version against the advisory.
  2. If you can't patch immediately, reduce exposure. Fortinet's interim workaround is to disable SSL VPN until you can upgrade. (Disabling only webmode is not sufficient.)
  3. Hunt, given the age. Because this has been exploitable for a long time, review VPN and appliance logs for anomalous sessions and signs of prior compromise before you assume patching alone closed the book.
  4. If you find indicators, respond. Rotate VPN and admin credentials, invalidate active sessions, and follow Fortinet's guidance for a compromised appliance.
  5. Confirm your exposure first. Verify whether you have an internet-facing FortiGate/FortiProxy running SSL VPN at all, and which firmware it's on.

How BreachRisk sees it

That first question — do we even have an exposed, affected FortiGate? — is what BreachRisk answers. Starting from little more than your domain, it discovers your internet-facing appliances, fingerprints the FortiOS SSL VPN interface and its firmware version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one. Because it's in KEV, it rises straight to the top of your results instead of getting lost in a scanner's backlog.

The point of a continuous, attacker's-eye view is that a years-old, still-exploited flaw doesn't wait for an audit to resurface — if an affected appliance is exposed, it's already on your radar.

References

See your cyber risk, proven.