VYPR
advisoryPublished Sep 17, 2026· 1 source

Fortinet FortiGate Exploit Allegedly for Sale on Dark Web

A threat actor claims to be selling a '1-day' remote code execution exploit for Fortinet FortiGate SSL VPNs, targeting FortiOS versions 7.2.x and 7.4.x.

A threat actor is reportedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that FortiOS 7.2.x and 7.4.x are affected. The advertisement, shared by Dark Web Intelligence, promotes what the seller describes as a “1-day” exploit with remote code execution capability, intended for initial access against exposed FortiGate SSL VPN services. The actor also claims to have a proof-of-concept video and states that pricing is available through private communication.

However, the listing lacks critical details such as a specific CVE, exact affected firmware builds, whether authentication is required, or a technical description of the alleged vulnerability. These omissions make it impossible to independently verify the claim or determine if it targets an undisclosed flaw, an older patched vulnerability, a bypass of an existing fix, or is a fraudulent offering.

FortiGate devices remain attractive targets for attackers due to their common deployment at enterprise network perimeters, providing essential firewall, VPN, and remote-access services. A successful pre-authentication remote code execution vulnerability in such a device could grant attackers an initial foothold, enable persistence, facilitate credential theft, allow pivoting into internal networks, or serve as a gateway for deploying further malware.

The alleged exploit sale emerges at a time when previously disclosed Fortinet vulnerabilities continue to be actively exploited. Security researchers have recently noted attacks involving CVE-2025-25249, an unauthenticated heap-based buffer overflow in FortiOS and FortiSwitchManager that can lead to command execution. Despite Fortinet releasing patches in January 2026, attackers reportedly began exploiting this vulnerability in real-world operations as early as July 2026.

Furthermore, threat actors are still abusing CVE-2024-21762, a critical out-of-bounds write flaw affecting the FortiOS and FortiProxy SSL VPN component. This vulnerability, which can allow unauthenticated remote code execution via specially crafted HTTP requests, has been linked to recent intrusions targeting exposed FortiGate systems.

Fortinet has previously advised organizations to disable SSL VPN if an immediate upgrade is not feasible. Security teams should treat this latest claim as a threat intelligence lead rather than confirmation of a new vulnerability. It is crucial to inventory all internet-facing FortiGate appliances, ensure FortiOS versions are supported and fully patched, restrict administrative and VPN access to trusted networks, and meticulously review logs for any anomalous SSL VPN activity.

Administrators should be vigilant for signs of compromise, including the creation of new administrator accounts, unexplained configuration changes, suspicious VPN sessions, unfamiliar processes running on the firewall, and unexpected outbound connections originating from the firewall appliance. Given that edge devices like FortiGates can provide privileged access to internal environments, any suspected compromise should trigger immediate credential rotation, a thorough configuration review, and a comprehensive incident response investigation.

Synthesized by Vypr AI
Fortinet FortiGate Exploit Allegedly for Sale on Dark Web · VYPR