Skip to content
Mass Exploitation of FortiManager Vulnerability CVE-2024-47575 Confirmed

Mass Exploitation of FortiManager Vulnerability CVE-2024-47575 Confirmed

First seen 17 Jun 2026, 12:42 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 18, 2026 at 12:13 UTC
  • CVE-2024-47575 allows unauthorized access to FortiManager devices.
  • Over 50 devices have been compromised, with sensitive data exfiltrated.
  • Mandiant tracks the exploiting group as UNC5820, active since June 2024.

CVE-2024-47575, known as FortiJump, has been actively exploited since June 2024, affecting over 50 FortiManager devices across various industries. The vulnerability allows unauthorized control of FortiManager appliances, enabling threat actors to execute arbitrary commands and exfiltrate sensitive configuration data. Mandiant identified a threat cluster, UNC5820, responsible for these exploits, which included staging configuration files and user credentials. The first observed exploitation attempt occurred on June 27, 2024, with subsequent attempts noted in September 2024. Organizations with exposed FortiManager devices are urged to conduct forensic investigations immediately. The vulnerability was officially published on October 23, 2024, and is included in CISA's KEV list due to active exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2024-02-15
CVE-2024-23113 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-06-27
First exploitation attempt observed
Mandiant noted multiple FortiManager devices receiving connections from a threat actor's IP, leading to data staging.
cloud.google.com
2024-09-23
Second exploitation attempt recorded
A second wave of exploitation was observed with similar indicators as the first attempt, indicating ongoing threat activity.
cloud.google.com
2024-10-23
CVE-2024-47575 published
The vulnerability was officially disclosed, detailing its critical nature and exploitation methods.
cloud.google.com

More articles in this cluster (2)

Following this threat?

Track Unc5820 and CVE-2024-23113 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed