Mass Exploitation of FortiManager Vulnerability CVE-2024-47575 Confirmed

Mass Exploitation of FortiManager Vulnerability CVE-2024-47575 Confirmed

First seen 17 Jun 2026, 12:42 UTC cloud.google.combishopfox.com 69.9

Article Content

Browse articles
ThreatCluster

CVE-2024-47575, known as FortiJump, has been actively exploited since June 2024, affecting over 50 FortiManager devices across various industries. The vulnerability allows unauthorized control of FortiManager appliances, enabling threat actors to execute arbitrary commands and exfiltrate sensitive configuration data. Mandiant identified a threat cluster, UNC5820, responsible for these exploits, which included staging configuration files and user credentials. The first observed exploitation attempt occurred on June 27, 2024, with subsequent attempts noted in September 2024. Organizations with exposed FortiManager devices are urged to conduct forensic investigations immediately. The vulnerability was officially published on October 23, 2024, and is included in CISA's KEV list due to active exploitation.

Key Points: • CVE-2024-47575 allows unauthorized access to FortiManager devices. • Over 50 devices have been compromised, with sensitive data exfiltrated. • Mandiant tracks the exploiting group as UNC5820, active since June 2024.

Timeline

2024-02-15
CVE-2024-23113 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-06-27
First exploitation attempt observed
Mandiant noted multiple FortiManager devices receiving connections from a threat actor's IP, leading to data staging.
cloud.google.com
2024-09-23
Second exploitation attempt recorded
A second wave of exploitation was observed with similar indicators as the first attempt, indicating ongoing threat activity.
cloud.google.com
2024-10-23
CVE-2024-47575 published
The vulnerability was officially disclosed, detailing its critical nature and exploitation methods.
cloud.google.com