Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5022 articles · 188920 vulns · 37/41 feeds (7d)
← Back to list
9.6
CVE-2024-55591KEVEXPLOITEDPATCHED
fortinet · fortiproxy

CVE-2024-55591: An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 thro

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Affected Products

VendorProductVersions
fortinetfortiproxy7.0.0, 7.2.0, 7.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
fortinetfortioscve_cpe95%

References

  • https://fortiguard.fortinet.com/psirt/FG-IR-24-535

Related News (5 articles)

Tier D
Infosecurity Magazine4h ago
Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure
→ No new info (linked only)
Tier D
BleepingComputer1d ago
US and South Korea warn of Gunra ransomware targeting govt agencies
→ No new info (linked only)
Tier D
The Record1d ago
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
→ No new info (linked only)
Tier C
Palo Alto Unit 4232d ago
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
→ No new info (linked only)
Tier B
CCCS Canada55d ago
AL26-014 – FortiBleed leak of thousands of compromised credentials impacting Fortinet devices
→ No new info (linked only)
CVSS 3.19.6 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
7.0.207.2.137.0.17
CWECWE-288
PublishedJan 14, 2025
Last enriched55d agov2
Tags
FortiBleed
Trending Score149🔥
Source articles5
Independent5
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-26035
CVE-2026-26035: An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.
Trending: 53
MEDIUMCVE-2026-70466
CVE-2026-70466: A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.
Trending: 49
MEDIUMCVE-2026-71408
CVE-2026-71408: A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.
Trending: 44
HIGHCVE-2026-70465
CVE-2026-70465: A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.
Trending: 43
HIGHCVE-2026-70468
CVE-2026-70468: A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.
Trending: 43

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Jan 14, 2025
Added to CISA KEV
Jan 14, 2025
Discovered by ZDM
Apr 1, 2026
Updated: cweIds, tags
Jun 18, 2026
Actively Exploited
Aug 5, 2026
Exploit Available
Aug 5, 2026
Patch Available
Aug 5, 2026

Version History

v2
Last enriched 55d ago
v2Tier B55d ago

Added new CWE ID related to authentication bypass and included the tag 'FortiBleed'.

cweIdstags
via CCCS Canada
v1132d ago

Initial creation