Attackers began exploiting Fortinet authentication bypass flaw CVE-2022-40684 against internet-facing devices shortly after the vulnerability was disclosed, according to SOC observations. The issue affects FortiOS, FortiProxy, and FortiSwitchManager, and allows unauthenticated attackers to send crafted HTTP/HTTPS requests that bypass authentication and gain access to the administrative interface.
Observed attacks started within days of disclosure, with defenders warning that public proof-of-concept code could accelerate broader exploitation. Organizations were urged to upgrade affected versions immediately or apply Fortinet’s mitigations, including disabling HTTP/HTTPS administrative access where possible and restricting administrative interface access to trusted IP addresses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC reported seeing attacks exploiting CVE-2022-40684 beginning on October 14, 2022, shortly after disclosure. The observed payload used an HTTP PUT request to /api/v2/cmdb/system/admin/admin with a forged Forwarded header and attempted to set an ssh-public-key1 value.
Fortinet publicly disclosed CVE-2022-40684 on October 10, 2022. The vulnerability affects FortiOS, FortiProxy, and FortiSwitchManager and allows authentication bypass via crafted HTTP/HTTPS requests to administrative interfaces.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.