Fortinet has detected the creation of a malicious file by a threat actor exploiting previously exploited RCE vulnerabilities in FortiOS and FortiGate products. This malicious file could allow read-only access to files on the device's file system, which may include configurations.
See the following resource for more information:
CISA recommends administrators review the Fortinet warning and:
- Update to FortiOS versions 7.6.2, 7.4.7, 7.2.11, 7.0.17, 6.4.16 to remove the malicious file and prevent recompromise.
- Review the configuration of all devices within scope.
- Reset potentially exposed credentials.
- As a temporary mitigation until the patch is applied, consider disabling the SSL-VPN functionality, since exploitation of the file requires SSL-VPN to be enabled.
Organizations should report incidents and anomalous activity to the CISA 24/7 Operations Center at Report@cisa.gov or (888) 282-0870.
For more information on mitigation: Recommended steps to execute in case of a... - Fortinet Community.



