"Fortinet Issues Urgent Warning on Active Exploitation of Critical SSL VPN Flaws"

TL;DR
Fortinet has disclosed a critical security flaw in FortiOS SSL VPN, likely being actively exploited, allowing for the execution of arbitrary code and commands. The vulnerability impacts multiple versions of FortiOS, and patches have been issued for other CVEs affecting FortiSIEM supervisor. Recent reports reveal Chinese state-sponsored actors exploiting known flaws in Fortinet devices, underscoring the growing threat faced by internet-facing edge devices lacking endpoint detection and response support.
Topics:businesstechnologysecurity#cybersecurity#exploitation#fortinet#ssl-vpn#technologysecurity#vulnerability
- Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active Exploitation The Hacker News
- New Fortinet RCE flaw in SSL VPN likely exploited in attacks BleepingComputer
- Fortinet urges patching N-day bug amid ongoing nation-state exploitation CSO Online
- Double trouble replay for Fortinet as it reissues critical FortiSIEM vulns The Register
- Fortinet Warns of New FortiOS Zero-Day SecurityWeek
Want the full story? Read the original reporting
Read on The Hacker News