bishopfox.com Mass Exploitation of FortiManager Vulnerability CVE-2024-47575 Confirmed
Article Content
- •CVE-2024-47575 allows unauthorized access to FortiManager devices.
- •Over 50 devices have been compromised, with sensitive data exfiltrated.
- •Mandiant tracks the exploiting group as UNC5820, active since June 2024.
CVE-2024-47575, known as FortiJump, has been actively exploited since June 2024, affecting over 50 FortiManager devices across various industries. The vulnerability allows unauthorized control of FortiManager appliances, enabling threat actors to execute arbitrary commands and exfiltrate sensitive configuration data. Mandiant identified a threat cluster, UNC5820, responsible for these exploits, which included staging configuration files and user credentials. The first observed exploitation attempt occurred on June 27, 2024, with subsequent attempts noted in September 2024. Organizations with exposed FortiManager devices are urged to conduct forensic investigations immediately. The vulnerability was officially published on October 23, 2024, and is included in CISA's KEV list due to active exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Unc5820 and CVE-2024-23113 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…