CVE-2024-55591: Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-01-14. EPSS: 94.1% chance of exploitation in the next 30 days.

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.

Affected products

  • Fortinet FortiOS: from 7.0.0, before 7.0.17 (fixed in 7.0.17)
  • Fortinet FortiProxy: from 7.0.0, before 7.0.20 (fixed in 7.0.20); from 7.2.0, before 7.2.13 (fixed in 7.2.13)

Published 2025-01-14. Last modified 2026-08-05.