Fortinet has identified a threat actor creating a malicious file from previously exploited RCE vulnerabilities in FortiOS and FortiGate products. This malicious file could allow read-only access to files on the devices' file system, which may include configurations. For more information, see the following resource:
CISA recommends administrators review the Fortinet alert and:
- Update to FortiOS versions 7.6.2, 7.4.7, 7.2.11, 7.0.17, 6.4.16 to remove the malicious file and prevent possible reinfection.
- Review the configuration of all affected devices.
- Reset potentially exposed credentials.
- As a temporary mitigation measure until the patch is applied, consider disabling the SSL-VPN functionality, as exploitation of the file requires SSL-VPN to be enabled.
Organizations should report incidents and anomalous activity to the CISA 24/7 Operations Center at Report@cisa.gov or (888) 282-0870.
For more information on mitigation: Recommended steps to execute in case of... - Fortinet Community .



