CVE detail
CVE-2022-40684
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
36 source links · newest first
- FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate DevicesQualys
rative interfaces and SSL-VPN gateways; this post maps eight Fortinet CVEs with associated Qualys detections, including CVE-2026-24858, CVE-2025-59718, and CVE-2025-59719. Large-scale credential-abuse activity has been publicly reported, and Fortinet confirmed credential reuse , brute-force activity, and prior exploitation of earlier FortiCloud SSO iss
vendorblog.qualys.comJul 8, 2026, 5:38 PM This blog details how attackers are actively exploiting Fortinet FortiGate firewalls vulnerable to CVE-2022-40684, with real-time insights from GreyNoise to help defenders understand and respond to these threats.
vendorwww.greynoise.ioJan 28, 2025, 12:00 AMNetwork administrators with Fortinet’s FortiGate next generation firewall in their IT environments are being warned to thoroughly scrutinize systems for possible compromise, following last week’s dump of stolen configuration and VPN credentials by a threat actor. “Patching is not enough,” tweeted cybersecurity researcher Florian Roth on Thursday. “If you take security seriously, you must run […]
newswww.csoonline.comJan 23, 2025, 11:51 PMA threat actor has leaked configuration files (aka configs) for over 15,000 Fortinet Fortigate firewalls and associated admin and user credentials. The collection has been leaked on Monday and publicized on an underground forum by the threat actor that goes by “Belsen_Group”, supposedly as a free offering to solidify the name of the group in the forum users’ memory. The leaked 1.6 GB archive contains folders ordered by country, and inside each are folders named … More →
newswww.helpnetsecurity.comJan 16, 2025, 11:01 AM- Earth Lusca expands its arsenal with SprySOCKS Linux malwareSecurity Affairs
China-linked threat actor Earth Lusca used a new Linux malware dubbed SprySOCKS in a recent cyber espionage campaign. Researchers from Trend Micro, while monitoring the activity of the China-linked threat actor Earth Lusca, discovered an encrypted file hosted on a server under the control of the group. Additional analysis led to the discovery of a […]
newssecurityaffairs.comSep 19, 2023, 7:51 AM - Top 12 vulnerabilities routinely exploited in 2022Help Net Security
Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →
newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM Fortinet addressed a new critical flaw, tracked as CVE-2023-27997, in FortiOS and FortiProxy that is likely exploited in a limited number of attacks. Fortinet has finally published an official advisory about the critical vulnerability, tracked as CVE-2023-27997 (CVSS score: 9.2), impacting FortiOS and FortiProxy. “A heap-based buffer overflow vulnerability [CWE-122] in FortiOS and FortiProxy SSL-VPN may allow a remote […]
newssecurityaffairs.comJun 13, 2023, 10:49 AMFortinet has warned customers that the critical CVE-2023-27997 vulnerability that was patched recently could be a zero-day exploited in limited attacks.
newswww.securityweek.comJun 13, 2023, 8:30 AMThe cybercrime underground has long functioned as an open market where sellers of products and services are paired with buyers and contractors. One of the most valuable commodities on this market are stolen credentials since they can provide attackers with access into networks, databases, and other assets owned by organizations. It’s no surprise to see […]
newswww.csoonline.comMar 10, 2023, 1:06 AM- Threat actors are offering access to corporate networks via unauthorized Fortinet VPN accessSecurity Affairs
Cyble observed Initial Access Brokers (IABs) offering access to enterprise networks compromised via a critical flaw in Fortinet products. Researchers at Cyble have observed initial access brokers (IABs) selling access to enterprise networks likely compromised via a recently patched critical flaw, tracked as CVE-2022-40684, in Fortinet products. In early October, Fortinet addressed the critical authentication bypass flaw, […]
newssecurityaffairs.comNov 29, 2022, 10:22 PM Security researchers at Cyble have observed initial access brokers (IABs) selling access to enterprise networks likely compromised via a recently patched critical vulnerability in Fortinet products.
newswww.securityweek.comNov 29, 2022, 12:02 PM- Fortinet fixed 16 vulnerabilities, 6 rated as high severitySecurity Affairs
Fortinet addressed 16 vulnerabilities in some of the company’s products, six flaws received a ‘high’ severity rate. One of the high-severity issues is a persistent XSS, tracked as CVE-2022-38374, in Log pages of FortiADC. The root cause of the issue is an improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC. A […]
newssecurityaffairs.comNov 3, 2022, 8:04 AM - Fortinet Patches 6 High-Severity VulnerabilitiesSecurityWeek
Fortinet on Tuesday informed customers about 16 vulnerabilities discovered in the company’s products, including six flaws that have been assigned a ‘high’ severity rating.
newswww.securityweek.comNov 2, 2022, 4:19 PM - Security Affairs newsletter Round 390Security Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. Daixin Team targets health organizations with ransomware, US agencies warn Threat actors exploit critical flaw in […]
newssecurityaffairs.comOct 23, 2022, 6:29 PM Learn how to use NodeZero from Horizon3.ai to secure your Fortinet appliances across on-prem, cloud, and hybrid networks at scale.
exploithorizon3.aiOct 18, 2022, 4:12 PMhentication bypass flaw which allows threat actors to run operations on a device’s administrative interface. Tracked as CVE-2022-40684 , the vulnerability carries a CVSS score of 9.6, and is therefore considered critical. RELATED RESOURCE Facilitating Fintech Reducing the risk of potential data interception among fintech solutions FREE DOWNLOAD Before
newswww.itpro.comOct 18, 2022, 3:50 PM- Over 17000 Fortinet devices exposed online are very likely vulnerable to CVE-2022-40684Security Affairs
Fortinet confirmed that many systems are still vulnerable to attacks exploiting the CVE-2022-40684 zero-day vulnerability. Fortinet is urging customers to address the recently discovered CVE-2022-40684 zero-day vulnerability. Unfortunately, the number of devices that have yet to be patched is still high. “After multiple notifications from Fortinet over the past week, there are still a significant number of […]
newssecurityaffairs.comOct 18, 2022, 7:56 AM Fortinet is concerned that many of its customers’ devices are still unprotected against attacks exploiting the recently disclosed zero-day vulnerability and the company has urged them to take action.
newswww.securityweek.comOct 17, 2022, 12:38 PM- Security Affairs newsletter Round 389Security Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. New PHP Version of Ducktail info-stealer hijacks Facebook Business accounts Palo Alto Networks fixed a high-severity […]
newssecurityaffairs.comOct 16, 2022, 9:37 AM - Week in review: 3FA, Fortinet firewalls under attack, and the riskiest connected devicesHelp Net Security
Lack of transparency, systemic risks weaken national cybersecurity preparedness Bob Kolasky, SVP for Critical Infrastructure at Exiger, previously served as Assistant Director for Cybersecurity and Infrastructure Security Agency (CISA), and in this Help Net Security interview talks about protecting critical infrastructure, the importance of information-sharing, national cybersecurity preparedness, and more. Cybercriminals are having it easy with phishing-as-a-service In this interview for Help Net Security, Immanuel Chavoya, Threat Detection Expert at SonicWall, talks about phishing-as-a-service (PaaS), … More →
newswww.helpnetsecurity.comOct 16, 2022, 8:30 AM HelpNetSecurity: 10/14/22 Horizon3.ai researchers have released a PoC exploit for CVE-2022-40684, the authentication bypass vulnerability affecting Fortinet‘s firewalls and secure web gateways, and soon after exploitation attempts started rising. Read the entire article here
exploithorizon3.aiOct 14, 2022, 6:22 PMHorizon3.ai researchers have released a PoC exploit for CVE-2022-40684, the authentication bypass vulnerability affecting Fortinet‘s firewalls and secure web gateways, and soon after exploitation attempts started rising. “[On Thursday], the Wordfence Threat Intelligence team began tracking exploit attempts targeting CVE-2022-40684 on our network of over 4 million protected websites,” Wordfence threat analyst Ram Gall shared. They have recorded several exploit attempts and requests from over 20 IP addresses, but most of those were attempts to … More →
newswww.helpnetsecurity.comOct 14, 2022, 2:06 PMDetails and a proof-of-concept (PoC) exploit have been published for the recent Fortinet vulnerability tracked as CVE-2022-40684, just as cybersecurity firms are seeing what appears to be the start of mass exploitation attempts.
newswww.securityweek.comOct 14, 2022, 10:02 AM- Experts released PoC exploit code for critical bug CVE-2022-40684 in Fortinet productsSecurity Affairs
Experts released the PoC exploit code for the authentication bypass flaw CVE-2022-40684 in FortiGate firewalls and FortiProxy web proxies. A proof-of-concept (PoC) exploit code for the authentication bypass vulnerability CVE-2022-40684 (CVSS score: 9.6) in FortiGate firewalls and FortiProxy web proxies has been released online. The vulnerability impacts FortiOS versions from 7.0.0 to 7.0.6 and from […]
newssecurityaffairs.comOct 14, 2022, 9:37 AM This morning, the Wordfence Threat Intelligence team began tracking exploit attempts targeting CVE-2022-40684 on our network of over 4 million protected websites. CVE-2022-40684 is a critical authentication bypass vulnerability in the administrative interface of Fortinet’s FortiGate firewalls, FortiProxy web proxies, and FortiSwitch Manager, and is being actively exploited in the wild¹,². At the time of … Read More
vendorwww.wordfence.comOct 13, 2022, 9:08 PMBleeping Computer: 10/13/22 Horizon3.ai security researchers released a proof-of-concept (PoC) exploit and a technical root cause analysis for this vulnerability today, following an announcement that a CVE-2022-40684 PoC will be made available this week. Read the entire article here
exploithorizon3.aiOct 13, 2022, 6:20 PMFortinet recently patched a critical authentication bypass vulnerability in their FortiOS, FortiProxy, and FortiProxySwitchManager projects (CVE-2022-40684) . This vulnerability gives an attacker the ability to login as an administrator on the effected system. To demonstrate the vulnerability in this writeup, we will be using FortiOS version 7.2.1
exploithorizon3.aiOct 13, 2022, 4:45 PMTechNewToday: 10/12/22 CISA added the flaw to the KEV catalog on Tuesday, a day after Fortinet revealed that an authentication bypass CVE-2022-40684 that was patched last week was already being exploited in the wild. Read the entire article here
exploithorizon3.aiOct 12, 2022, 6:17 PMIntroduction The recent FortiOS / FortiProxy / FortiSwitchManager CVE has been reportedly exploited in the wild. We would like to provide additional insight into the vulnerability so users can begin to determine if they have been compromised. In this post we discuss enabling logging and IOCs for FortiOS 7.2.1. These steps will likely work on […]
exploithorizon3.aiOct 11, 2022, 7:33 PMAfter privately warning customers last week that they need to patch or mitigate CVE-2022-40684, a critical vulnerability affecting FortiOS, FortiProxy, and FortiSwitchManager, Fortinet has finally confirmed that it “is aware of an instance where this vulnerability was exploited.” But their advice to organizations to immediately check their systems for a specific indicator of compromise makes it sound like they believe more widespread attacks have happened or are happening. About CVE-2022-40684 CVE-2022-40684 is an authentication bypass … More →
newswww.helpnetsecurity.comOct 11, 2022, 11:27 AMFortinet has confirmed that the critical vulnerability whose existence came to light last week is a zero-day flaw that has been exploited in at least one attack.
newswww.securityweek.comOct 11, 2022, 10:36 AMFortinet has confirmed that the recently disclosed critical authentication bypass issue (CVE-2022-40684) is being exploited in the wild. Last week, Fortinet addressed a critical authentication bypass flaw, tracked as CVE-2022-40684, that impacted FortiGate firewalls and FortiProxy web proxies. An attacker can exploit the vulnerability to log into vulnerable devices. “An authentication bypass using an alternate […]
newssecurityaffairs.comOct 10, 2022, 8:47 PMSecurity Affairs: 10/10/22 Fortinet has confirmed that the recently disclosed critical authentication bypass issue (CVE-2022-40684) is being exploited in the wild. Read the entire article here
exploithorizon3.aiOct 10, 2022, 6:07 PMFortinet has privately informed some customers about a critical and remotely exploitable vulnerability that poses a significant risk.
newswww.securityweek.comOct 10, 2022, 10:08 AM- 10th October – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 10th October, please download our Threat Intelligence Bulletin. Top Attacks and Breaches CommonSpirit Health, the second-largest nonprofit hospital chain in the U.S with 140 hospitals and over 1,000 facilities in 21 states, suffered a cybersecurity incident that disrupted medical services across the country. Facilities in Iowa, Nebraska, […]
vendorresearch.checkpoint.comOct 10, 2022, 9:27 AM - Fortinet urges customers to immediately fix a critical authentication bypass flaw in FortiGate and FortiProxySecurity Affairs
Fortinet addressed a critical authentication bypass vulnerability that impacted FortiGate firewalls and FortiProxy web proxies. Fortinet addressed a critical authentication bypass flaw, tracked as CVE-2022-40684, that impacted FortiGate firewalls and FortiProxy web proxies. An attacker can exploit the vulnerability to log into vulnerable devices. “An authentication bypass using an alternate path or channel [CWE-88] in […]
newssecurityaffairs.comOct 7, 2022, 2:37 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-35843CVSS 8.1 · High
An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions,…
- CVE-2025-61624CVSS 6.0 · Medium
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, Fort…
- CVE-2025-59718CVSS 9.8 · Critical
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0…
- CVE-2025-22258CVSS 6.5 · Medium
A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1…
- CVE-2024-26008CVSS 5.3 · Medium
An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and…
- CVE-2024-26009CVSS 8.1 · High
An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all version…