• News/
  • https://www.theregister.com/2025/01/21/fortinet_firewalls_still_vulnerable/

Patch procrastination leaves 50,000 Fortinet firewalls vulnerable to zero-day

The Register
·
Connor Jones
·
Published Jan 21, 2025
·
Updated

Fortinet customers need to get with the program and apply the latest updates as nearly 50,000 management interfaces are still vulnerable to the latest zero-day exploit. Data from the Shadowserver Foundation shows 48,457 Fortinet boxes are still publicly exposed and haven't had the patch for CVE-2024-55591 applied, despite stark warnings issued over the past seven days. The situation has not improved over time either. Shadowserver began tracking the number of exposed appliances on January 16, two days after the CVE identifier for the zero-day was issued, and even then just shy of 52,000 instances were vulnerable. Customers in Asia are the most exposed, with 20,687 vulnerable firewalls still reachable over the internet, while North America and Europe trail with 12,866 and 7,401 respectively. A reminder to those still dawdling over patching this one, Fortinet confirmed CVE-2024-55591 is being actively exploited and it's also on CISA's KEV catalog. Don't be like the 86,000-plus customers who didn't patch the last one. Speaking to The Register about the issue last week, Arctic Wolf Labs' lead threat intelligence researcher Stefan Hostetler said exploits have been widespread, opportunistic, and date back to December. He added that once they've pwned their target, attackers appear to be stealing credentials and using them to worm their way through the victim's network with admin privileges. The rest of the details are still being gathered, but - needless to say - an intruder with ad...

Read full article

Affected Software

3 affected components
Fortinet FortiOS
Fortinet FortiProxy
Fortinet Fortinet
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the vulnerability of nearly 50,000 Fortinet firewalls due to a zero-day exploit and the urgent need for patches.

2

What security implications are discussed in the article?

The security implications include potential unauthorized access and exploitation of unpatched management interfaces in Fortinet firewalls.

3

What products or software are affected by the vulnerability?

The affected products include Fortinet FortiOS and Fortinet FortiProxy.

4

Why are the Fortinet firewalls still vulnerable according to the article?

The firewalls remain vulnerable due to delays in patching by Fortinet customers.

5

What can users do to protect their Fortinet firewalls from exploitation?

Users should ensure they apply the latest security updates to their Fortinet devices promptly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203