Fortinet FortiManager Under Attack: Critical CVE-2024-47575 Vulnerability

Shadowserver has issued a critical warning about the widespread exploitation of Fortinet FortiManager devices due to the recently disclosed CVE-2024-47575 vulnerability, termed “FortiJump.” This vulnerability, with a CVSS score of 9.8/10, allows unauthenticated remote attackers to execute arbitrary code on affected systems, targeting sensitive data exfiltration as their primary objective. The alert indicates a highly concerning situation for organizations relying on FortiManager, urging immediate remedial measures to mitigate potential security breaches.

Fortinet has confirmed the active exploitation of this vulnerability and has called for urgent action from all users of FortiManager systems. In a detailed Special Report, Shadowserver categorizes affected devices into two groups: those that have been compromised and those that have been targeted but not yet confirmed as compromised. It strongly emphasizes the necessity of changing credentials for all managed devices connected to the vulnerable FortiManager systems. This task is rendered more complex by the potential presence of multiple IP addresses and NAT device traversal, complicating the identification process.

The Attack and the Threat Actor

Mandiant has attributed these attacks to a threat actor known as UNC5820, bringing to light that the exploitation has been ongoing since at least June 27, 2024. According to Mandiant’s findings, more than 50 FortiManager appliances across a range of industries have been targeted in this mass compromise. This highlights the critical nature of the “FortiJump” vulnerability and the rapid, widespread exploitation by threat actors. The situation underscores the need for organizations to stay vigilant and apply necessary security measures without delay.

Organizations using FortiManager are urged to immediately apply patches provided by Fortinet or implement recommended workarounds if patching is not feasible. The directive from Shadowserver’s report highlights the importance of these measures in securing systems and curbing further exploits. As threat actors continue to capitalize on this vulnerability, cybersecurity experts stress the importance of monitoring for any indicators of compromise and reporting suspicious activities related to FortiManager deployments promptly.

Recommendations for Organizations

Shadowserver has issued an urgent warning regarding the widespread exploitation of Fortinet FortiManager devices, linked to the recently disclosed CVE-2024-47575 vulnerability known as “FortiJump.” This vulnerability, boasting a CVSS score of 9.8 out of 10, enables unauthenticated remote attackers to execute arbitrary code on the affected systems, primarily aiming to exfiltrate sensitive data. The alert underscores a highly alarming situation for organizations relying on FortiManager, urging them to take swift remedial measures to prevent potential security breaches.

Fortinet has acknowledged the active exploitation of this flaw and is calling for immediate action from all FortiManager users. In a comprehensive Special Report, Shadowserver categorizes affected devices into two groups: those compromised and those targeted but not yet confirmed as compromised. It strongly emphasizes the critical need to change credentials for all managed devices connected to vulnerable FortiManager systems. This task is further complicated by the potential presence of multiple IP addresses and the traversal of NAT devices, making identification more challenging.

Explore more

Is ChatGPT the Future of Hotel and Travel Advertising?

The transition from scanning data to seeking synthesized advice represents a permanent change in how tourism destinations and luxury resorts must approach digital visibility. As the travel industry reaches a critical juncture in 2026, the reliance on static search results has dwindled in favor of interactive, intelligent dialogue. Syndacast, a prominent agency in the Asia-Pacific region, has recognized this evolution

Can Tokenized Deposits Transform Canada’s Financial Future?

Regulated institutional trust is being combined with blockchain automation to create a foundation for a twenty-four-seven tokenized economy in Canada. This transition represents a significant departure from the traditional financial architecture that has governed the nation for decades. Historically, Canadian commercial bank deposits existed as static entries within private, siloed ledgers, requiring complex reconciliation processes and limited by the operational

How Is CyphaLab Bridging the Gap Between TradFi and DeFi?

The movement of assets between traditional brokerage systems and decentralized liquidity venues is streamlined through a specialized transaction orchestration layer. In the current economic climate of 2026, the global financial industry is witnessing a pivotal shift as blockchain technology moves beyond its experimental roots to become a core foundation of asset management. CyphaLab has emerged as a major driver of

Why Did Sequans Abandon Its Bitcoin Treasury Strategy?

The official termination of the Bitcoin treasury strategy on September 24, 2026, allowed the firm to redirect all resources toward its expanding 4G and 5G cellular solutions. This strategic pivot marked the end of a high-stakes financial journey for Sequans Communications, which had initially sought to redefine the role of digital assets within the semiconductor industry. Throughout the previous fifteen

Will AI Data Centers Define the Future of Hamilton?

The defeat of the proposed development moratorium was influenced by concerns that a blanket ban might exceed the city’s legal jurisdiction and lead to litigation. This legislative turning point has placed Hamilton at a pivotal crossroads where the burgeoning global industry of artificial intelligence (AI) intersects directly with local environmental stewardship and complex urban planning strategies. As the municipal election