FortiOS auth bypass CVE-2024-55591 exploited
A FortiOS authentication bypass flaw (CVE-2024-55591) is being actively exploited, including confirmed attacks in Japan, to gain admin access.
IPA Japan issued an advisory on a Fortinet FortiOS vulnerability, CVE-2024-55591, which allows an unauthenticated remote attacker to bypass authentication and obtain administrator privileges. Fortinet confirmed exploitation of this flaw in the wild at the time of initial disclosure in January 2025.
In a May 2025 update, IPA reported that attacks believed to exploit this vulnerability have been observed within Japan, and warned that damage could continue to spread. Fortinet has since added indicators of compromise to its advisory and released patched versions along with mitigation guidance. IPA urges affected organizations to apply vendor-provided updates or workarounds urgently and to use the published IoCs to check for signs of compromise.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20250115.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free