Hackers Allegedly Selling Fortinet FortiGate 1-Day Vulnerability on Underground Forums
An unverified underground listing offers a claimed FortiGate SSL VPN RCE exploit for FortiOS 7.2.x/7.4.x amid ongoing exploitation of known Fortinet flaws.
Dark Web Intelligence shared an advertisement for a private '1-day' remote code execution exploit targeting FortiGate SSL VPN appliances on FortiOS 7.2.x and 7.4.x, with a claimed proof-of-concept video but no CVE, firmware builds, or technical details. The listing coincides with confirmed in-the-wild exploitation of CVE-2025-25249, an unauthenticated heap-based buffer overflow patched in January 2026 but exploited since July 2026, and CVE-2024-21762, a critical out-of-bounds write in the FortiOS and FortiProxy SSL VPN component. Fortinet has advised disabling SSL VPN where immediate upgrades are not possible.
- Seller claims a PoC video and private-pricing RCE exploit for initial access against exposed SSL VPN services.
- No CVE, affected builds, or technical details provided; could be a new flaw, patched bug, or fraud.
- CVE-2025-25249 heap overflow was patched January 2026 but exploited in real attacks since July 2026.
- CVE-2024-21762 out-of-bounds write in SSL VPN continues to be abused against exposed FortiGate systems.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21762 | Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted. Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority. | 9.8 | 84% | KEV ransomware |
| mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans) | |
| CVE-2025-25249 | Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known. Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product. | 9.8 | 2% | KEV PoC |
| mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants) |
Full article509 words · extracted from cybersecuritynews.com · click to collapse
A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that FortiOS 7.2.x and 7.4.x are affected. The listing has not been independently verified and does not confirm the existence of a new FortiGate zero-day vulnerability.
The advertisement, shared by Dark Web Intelligence, promotes what the seller describes as a “1-day” exploit with remote code execution capability.
The exploit is reportedly intended for initial access against exposed FortiGate SSL VPN services. The actor also claims to have a proof-of-concept video and says pricing is available through private communication.
However, the listing does not name a CVE, identify exact affected firmware builds, explain whether authentication is required, or provide a technical description of the alleged vulnerability.
These omissions make it impossible to determine whether the claimed exploit targets an undisclosed flaw, an older patched vulnerability, a bypass of an existing fix, or a fraudulent product.
Hackers Sell Fortinet FortiGate 1-Day Vulnerability
FortiGate devices remain high-value targets because they are commonly deployed at enterprise network edges to provide firewall, VPN, and remote-access services.
A working pre-authentication remote code execution bug in such an appliance could allow attackers to gain an initial foothold, establish persistence, steal credentials, pivot into internal networks, or deploy follow-on malware.

The claim also arrives amid ongoing exploitation of previously disclosed Fortinet vulnerabilities. Security researchers recently reported attacks involving CVE-2025-25249, an unauthenticated heap-based buffer overflow in FortiOS and FortiSwitchManager that can enable command execution through crafted requests.
Fortinet released patches in January 2026, but reports indicate attackers began exploiting the vulnerability in real-world operations in July 2026. Fixed FortiOS versions include 7.4.9 and 7.2.12 for the affected release branches.
Separately, attackers have continued to abuse CVE-2024-21762, a critical out-of-bounds write flaw in the FortiOS and FortiProxy SSL VPN component.
The vulnerability can allow unauthenticated remote code execution through specially crafted HTTP requests and has been linked to recent intrusions targeting exposed FortiGate systems.
According to a Dark Web Intelligence post on X, Fortinet previously advised organizations to disable SSL VPN when an immediate upgrade is not possible. Organizations should treat the alleged exploit sale as a threat-intelligence lead, not confirmation of a newly discovered vulnerability.
Security teams should immediately inventory all internet-facing FortiGate appliances, verify that FortiOS versions are supported and fully patched, restrict administrative and VPN access to trusted networks where possible, and review logs for unexpected SSL VPN activity.
Administrators should also look for new administrator accounts, unexplained configuration changes, suspicious VPN sessions, unfamiliar processes, and outbound connections from firewall appliances.
Because edge devices can provide privileged access to internal environments, a suspected compromise should trigger credential rotation, configuration review, and a broader incident-response investigation.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/hackers-selling-fortinet-fortigate-1-day-vulnerability/