Vulnerability report

Exploited in the wild Confirmed confidence In CISA KEV

CVE-2022-40684

Fortinet FortiOS Authentication Bypass

Fortinet FortiOS · FortiOS 7.2.1, 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; FortiProxy 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; FortiSwitchManager 7.2.0, 7.0.0

Severity
CVSS 9.8 · Critical
Confidence
Confirmed
Exploit status
Exploited in the wild
EPSS
100.0%
First observed
—
Last observed
—

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2022-40684 is an unauthenticated vulnerability affecting Fortinet FortiOS and 2 other products. An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1...

Is it exploited?

Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.

Who is affected?

Fortinet FortiOS fortios 7.2.1, 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; fortiproxy 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; fortiswitchmanager 7.2.0, 7.0.0.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

Fortinet FortiOS Authentication Bypass

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

Fortinet Affected
Fortinet FortiOS, FortiProxy, FortiSwitchManager
FortiOS 7.2.1, 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; FortiProxy 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; FortiSwitchManager 7.2.0, 7.0.0
Published
18 Oct 2022
Exploitation Reported
11 Oct 2022
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction
None

Tags

metasploit edge ransomware nuclei_scanner ios malware cisa

CVE References

Exploitation evidence

Why Previdian marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

CISA

Recorded 11 Oct 2022

A trusted third party reported exploitation.

Used in malware

CISA

Recorded 11 Oct 2022

Malware families have been linked to exploitation of this CVE.

Proof of concept available

Recorded 28 Apr 2025

Public scanner or PoC coverage increases practical exploitability.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the Previdian Pro API.

Learn about Pro API access
Source Added
CISA First 2022-10-11 00:00 UTC
The Shadowserver 2026-06-01 00:00 UTC
CVE 2026-08-06 04:30 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
User-Agents
Callback hosts
0
0
0

Request targets and User-Agents available in Pro. Callback host details available in Enterprise.

Virtual patch status

No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

9.8 Critical

Potential damage if exploited. Separate from whether attackers are using it.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C

EPSS

100.0%

Estimated chance of exploitation in the next 30 days. Previdian's warning comes from evidence, not this score.

Recent mention · Ransomware.live

🏴‍☠️ Deadlock has just published a new victim : Saber1

Saber1 Technologies LLC is a American supplier and distributor of machine vision components, industrial cameras and image processing systems.

Read full advisory

All Mentions

Recent mention · Ransomware.live

🏴‍☠️ Deadlock has just published a new victim : Saber1

Ransomware.live · 09 Oct 2026

Saber1 Technologies LLC is a American supplier and distributor of machine vision components, industrial cameras and image processing systems.

Recent mention · Ransomware.live

🏴‍☠️ Thegentlemen has just published a new victim : Saskatoon Tribal Council

Ransomware.live · 09 Oct 2026

sktc.sk.ca zoominfo.com/c/saskatoon-tribal-council-inc/215335121 Saskatoon Tribal Council (STC) is a non-profit tribal council founded in 1982 in Saskatoon, Saskatchewan (Treaty 6), uniting 7 First Nations with 14,000+ members. Led by Tribal Chief Mark Arcand (since 2017), STC employs 500–600+ people across 5 corporations (health, housing, urban services, investments, community development). Head-body revenue is $14–17M/year (federal ISC funding being the largest source), while the whole group is estimated at ~$45M. Its biggest asset is a stake in Dakota Dunes Casino & Resort ($70M...

Recent mention · Ransomware.live

🏴‍☠️ Thegentlemen has just published a new victim : Aquatech

Ransomware.live · 09 Oct 2026

aquatech.com zoominfo.com/c/aquatech-international-llc/2523742 Aquatech International Corporation is a private water treatment technology company founded in 1981 and headquartered in Canonsburg, Pennsylvania, with operations in 26 countries and 1,000+ projects across 60+ countries. It generates estimated annual revenue of $105–165M and employs 900–1,368 people globally (growing +31% per year). Aquatech is the world's leading Zero Liquid Discharge (ZLD) provider (160+ installations) and a major desalination player — its Corpus Christi, Texas plant (30 MGD) will be the third-largest SWRO...

Recent mention · Ransomware.live

🏴‍☠️ Nightspire has just published a new victim : Asociación de Escribanos del Uruguay

Ransomware.live · 08 Oct 2026

[AI generated] The Asociación de Escribanos del Uruguay is a professional association representing notaries (escribanos) in Uruguay. It operates within the legal services industry, providing support, regulation guidance, continuing education, and professional representation for notarial practitioners. The organization promotes standards of notarial practice, ethics, and legal certainty in document authentication and property transactions. It is based in Montevideo, Uruguay, and serves the national notarial community.

Recent mention · Ransomware.live

🏴‍☠️ Qilin has just published a new victim : Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi

Ransomware.live · 06 Oct 2026

N/A

Recent mention · Ransomware.live

🏴‍☠️ Thegentlemen has just published a new victim : Auren

Ransomware.live · 30 Sep 2026

auren.es zoominfo.com/c/auren/1115886722 AUREN (founded 1998, Madrid) is Spain's leading home-grown multidisciplinary professional-services firm — audit, legal/tax advisory, consulting and corporate finance — with €104 million revenue in Spain and 1,100+ staff in 15 offices (2,500+ people and 62 offices worldwide). Founded and chaired by Mario Alonso Ayala, it sells an integrated "Big Four-style" service portfolio to mid-market companies with a "humanist, close-to-client" culture, plus standout niches in forensic/expert-witness work, public-sector audit and M&A. In March 2025, Dutch private...

Recent mention · Ransomware.live

🏴‍☠️ Thegentlemen has just published a new victim : Drinks Wines Spirits

Ransomware.live · 30 Sep 2026

drinks.com.tw zoominfo.com/c/drinks-wines--spirits-co-ltd/425924055 DRINKS / Oak Barrel (橡木桶洋酒, Drinks Wines & Spirits Co., Ltd.) (founded 1993, Taipei) is Taiwan's largest liquor retail and import chain — 33–35 stores nationwide with about NT$2 billion (US$60M) annual revenue and 200–300 staff. Founded by "godfather of imported liquor" Chen Chun-an (died February 2026 at 80), it pioneered the wine-tasting culture in Taiwan through its Wine Party magazine, six tasting classrooms and a discount-store format with near-franchise store-manager economics. Beyond retail, it holds exclusive Taiwan...

Recent mention · Ransomware.live

🏴‍☠️ Incransom has just published a new victim : bcx.co.za

Ransomware.live · 29 Sep 2026

www.bcx.co.za BCX (Business Connexion) https://www.zoominfo.com/c/business-connexion-pty-ltd/372844609 Total leak: 500 GB 4,224,088 Files, 596,613 Folders The leak includes source code, technical documentation and other confidential information. Source code: 6 fully functional business applications 15+ integration libraries/modules 10+ test and utility projects BUSINESS APPLICATIONS 1) Cemetery Management / Cemres 2) mSCOA Posting Level Creator 3) SolarReceipting 4) PortalSSO / Solution_Menu 5) StopWatch Reports 6) ChangeRequestManager INTEGRATION PLATFORM 1....

Recent mention · Ransomware.live

🏴‍☠️ Qilin has just published a new victim : Island

Ransomware.live · 27 Sep 2026

N/A

Recent mention · Ransomware.live

🏴‍☠️ Qilin has just published a new victim : Inversiones Bolívar

Ransomware.live · 24 Sep 2026

N/A

Recent mention · SOCRadar

Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline

SOCRadar · 24 Sep 2026

Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline SOCRadar Threat Research Unit (STRU) has uncovered an end-to-end cybercrime operation dubbed Operation Master, in which a threat actor c

Recent mention · Ransomware.live

🏴‍☠️ Krybit has just published a new victim : www.jonesthegrocer.com

Ransomware.live · 24 Sep 2026

Jones the Grocer is a premium gourmet food retail and cafe brand founded in 1996 in Sydney, Australia, originally launch...

Recent mention · Ransomware.live

🏴‍☠️ Medusalocker has just published a new victim : Seznam

Ransomware.live · 23 Sep 2026

Organization with 115 emails extracted. Domain: seznam.cz

Recent mention · Ransomware.live

🏴‍☠️ Thegentlemen has just published a new victim : Grupolider

Ransomware.live · 21 Sep 2026

grupolider-ao.com zoominfo.com/c/grupolider/429885445 Grupolider is an Angolan diversified holding company founded in 1999, headquartered in Catete (Luanda province). The group operates in agriculture, logistics, freight forwarding, construction, and furniture manufacturing, with its flagship business being Novagrolider — the largest agricultural producer in Angola. Novagrolider farms around 20,000 hectares of land and produces roughly 150,000 tons of food per year (bananas, vegetables, fruit, and dairy), while the group employs over 3,200 direct staff. The company exports to Portugal,...

Recent mention · Ransomware.live

🏴‍☠️ Lockbit5 has just published a new victim : hygear.com

Ransomware.live · 18 Sep 2026

yGear specializes in providing reliable and affordable on-site and on-demand hydrogen and industrial...

Recent mention · Ransomware.live

🏴‍☠️ Ransomhouse has just published a new victim : Pertamina

Ransomware.live · 17 Sep 2026

Pertamina is an energy company primarily in the oil and gas sector. The company provides services for new and renewable energy, and other activities related to or supporting business activities in energy.

Recent mention · Ransomware.live

🏴‍☠️ Interlock has just published a new victim : City of Fort Smith Arkansas

Ransomware.live · 15 Sep 2026

The City of Fort Smith is committed to providing high-quality, resident-focused services to foster a thriving community. This is how they try to position themselves, but in reality, they are very negligent towards their residents and organizations within the city due to their negligent attitude towards security and lack of desire to solve problems, were compromised resulting in a major leak of confidential data over 5.6 TB of data, which includes key infrastructure facilities of Fort Smith (Public Safety System: Police Station, Fire Department, Communications Center (responsible for the 911...

Recent mention · Ransomware.live

🏴‍☠️ Thegentlemen has just published a new victim : Somit

Ransomware.live · 15 Sep 2026

somit.com zoominfo.com/c/somit/372548242 Guatemalan IT systems integrator founded in 1994 — designing, deploying and maintaining data networks, telecommunications, security systems, data-center engineering (power/cooling) and telemedicine & distance-learning interactive platforms for Guatemala's corporate and government sectors. In-house certified engineering staff; anchor clients include banks, universities and government institutions. A classic invisible Central-American integrator: 30+ years in the market, stable demand from banks and the state, near-zero international digital footprint

Recent mention · Ransomware.live

🏴‍☠️ Doommageddon has just published a new victim : INCOR Group

Ransomware.live · 13 Sep 2026

Status: upcoming | Data size: — | Files: 0 files | Deadline: 2026-09-20T00:00:00Z

Recent mention · Ransomware.live

🏴‍☠️ Krybit has just published a new victim : www.ibnsinatrust.com

Ransomware.live · 12 Sep 2026

The Ibn Sina Trust is a pioneering Bangladeshi non-profit welfare trust and major healthcare provider founded on June 30...

Recent mention · Ransomware.live

🏴‍☠️ Krybit has just published a new victim : lasultanahotels.com

Ransomware.live · 12 Sep 2026

La Sultana Hotel Group is a Moroccan luxury boutique hotel group created in the year 2000, targeting discerning traveler...

Recent mention · Tenable Blog

CVE-2025-32756: Zero-Day Vulnerability in Multiple Fortinet Products Exploited in the Wild

Tenable Blog · 14 May 2025

Fortinet has observed threat actors exploiting CVE-2025-32756, a critical zero-day arbitrary code execution vulnerability which affects multiple Fortinet products including FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera.BackgroundOn May 13th, Fortinet published a security advisory (FG-IR-25-254) for CVE-2025-32756, a critical arbitrary code execution vulnerability affecting multiple Fortinet products.CVEDescriptionCVSSv3CVE-2025-32756An arbitrary code execution vulnerability in FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera9.6AnalysisCVE-2025-32756 is an...

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Fortinet - Authentication Bypass

nuclei · Created Unknown

fortinet_authentication_bypass_cve_2022_40684

metasploit · Created Unknown

Metasploit module for CVE-2022-40684

Timeline

From disclosure to observed exploitation

  1. 04:30 UTC

    KEV confirmed by CVE

    Exploitation attested by an external source

  2. 00:00 UTC

    KEV confirmed by The Shadowserver

    Exploitation attested by an external source

  3. 15:02 UTC

    Metasploit module available

    Exploit module available

  4. 15:02 UTC

    Public PoC available

    Public proof-of-concept code published

  5. 00:00 UTC

    Nuclei template available

    Scanner coverage available

  6. 00:00 UTC

    CVE published

    Vulnerability disclosed publicly

  7. 00:00 UTC

    Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  8. 00:00 UTC

    First public exploitation report

    Exploit observed in malware

  9. 00:00 UTC

    CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2022-40684

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2022-40684",
  "confidence": "Confirmed",
  "cvss_score": 9.8,
  "cvss_estimated": false,
  "epss_score": 0.99984,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}