Security News > 2024 > February > New Fortinet RCE bug is actively exploited, CISA confirms

New Fortinet RCE bug is actively exploited, CISA confirms
2024-02-09 21:02

CISA confirmed today that attackers are actively exploiting a critical remote code execution bug patched by Fortinet on Thursday.

CISA's announcement comes one day after Fortinet published a security advisory saying the flaw was "Potentially being exploited in the wild."

While the company has yet to share more details regarding potential CVE-2022-48618, CISA has added the vulnerability to its Known Exploited Vulnerabilities Catalog, warning that such bugs are "Frequent attack vectors for malicious cyber actors" posing "Significant risks to the federal enterprise."

New Fortinet RCE flaw in SSL VPN likely exploited in attacks.

CISA: Critical Ivanti auth bypass bug now actively exploited.

CISA warns of patched iPhone kernel bug now exploited in attacks.


News URL

https://www.bleepingcomputer.com/news/security/new-fortinet-rce-bug-is-actively-exploited-cisa-confirms/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2024-01-09 CVE-2022-48618 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apple products
The issue was addressed with improved checks.
local
high complexity
apple CWE-367
7.0

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Fortinet 164 56 387 164 77 684