What it is
CVE-2022-40684 is an unauthenticated vulnerability affecting Fortinet FortiOS and 2 other products. An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1...
Vulnerability report
Fortinet FortiOS Authentication Bypass
Fortinet FortiOS · FortiOS 7.2.1, 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; FortiProxy 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; FortiSwitchManager 7.2.0, 7.0.0
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2022-40684 is an unauthenticated vulnerability affecting Fortinet FortiOS and 2 other products. An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Fortinet FortiOS fortios 7.2.1, 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; fortiproxy 7.2.0, 7.0.6, 7.0.5, 7.0.4, 7.0.3, 7.0.2, 7.0.1, 7.0.0; fortiswitchmanager 7.2.0, 7.0.0.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
CISA
A trusted third party reported exploitation.
CISA
Malware families have been linked to exploitation of this CVE.
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2022-10-11 00:00 UTC |
| The Shadowserver | 2026-06-01 00:00 UTC |
| CVE | 2026-08-06 04:30 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
Metasploit template detected 28 Apr 2025.
View Metasploit template (opens in new tab)No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Scanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/fortinet_authentication_bypass_cve_2022_40684.rb | 28 Apr 2025 |
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-40684.yaml | 25 Apr 2025 |
Risk and context
CVSS v3.1
Potential damage if exploited. Separate from whether attackers are using it.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C
EPSS
100.0%
Estimated chance of exploitation in the next 30 days. Previdian's warning comes from evidence, not this score.
Recent mention · Ransomware.live
Saber1 Technologies LLC is a American supplier and distributor of machine vision components, industrial cameras and image processing systems.
Read full advisoryRecent mention · Ransomware.live
🏴☠️ Deadlock has just published a new victim : Saber1Ransomware.live · 09 Oct 2026
Saber1 Technologies LLC is a American supplier and distributor of machine vision components, industrial cameras and image processing systems.
Recent mention · Ransomware.live
🏴☠️ Thegentlemen has just published a new victim : Saskatoon Tribal CouncilRansomware.live · 09 Oct 2026
sktc.sk.ca zoominfo.com/c/saskatoon-tribal-council-inc/215335121 Saskatoon Tribal Council (STC) is a non-profit tribal council founded in 1982 in Saskatoon, Saskatchewan (Treaty 6), uniting 7 First Nations with 14,000+ members. Led by Tribal Chief Mark Arcand (since 2017), STC employs 500–600+ people across 5 corporations (health, housing, urban services, investments, community development). Head-body revenue is $14–17M/year (federal ISC funding being the largest source), while the whole group is estimated at ~$45M. Its biggest asset is a stake in Dakota Dunes Casino & Resort ($70M...
Recent mention · Ransomware.live
🏴☠️ Thegentlemen has just published a new victim : AquatechRansomware.live · 09 Oct 2026
aquatech.com zoominfo.com/c/aquatech-international-llc/2523742 Aquatech International Corporation is a private water treatment technology company founded in 1981 and headquartered in Canonsburg, Pennsylvania, with operations in 26 countries and 1,000+ projects across 60+ countries. It generates estimated annual revenue of $105–165M and employs 900–1,368 people globally (growing +31% per year). Aquatech is the world's leading Zero Liquid Discharge (ZLD) provider (160+ installations) and a major desalination player — its Corpus Christi, Texas plant (30 MGD) will be the third-largest SWRO...
Recent mention · Ransomware.live
🏴☠️ Nightspire has just published a new victim : Asociación de Escribanos del UruguayRansomware.live · 08 Oct 2026
[AI generated] The Asociación de Escribanos del Uruguay is a professional association representing notaries (escribanos) in Uruguay. It operates within the legal services industry, providing support, regulation guidance, continuing education, and professional representation for notarial practitioners. The organization promotes standards of notarial practice, ethics, and legal certainty in document authentication and property transactions. It is based in Montevideo, Uruguay, and serves the national notarial community.
Recent mention · Ransomware.live
🏴☠️ Qilin has just published a new victim : Ciftay Insaat Taahhut Ve Ticaret Anonim SirketiRansomware.live · 06 Oct 2026
N/A
Recent mention · Ransomware.live
🏴☠️ Thegentlemen has just published a new victim : AurenRansomware.live · 30 Sep 2026
auren.es zoominfo.com/c/auren/1115886722 AUREN (founded 1998, Madrid) is Spain's leading home-grown multidisciplinary professional-services firm — audit, legal/tax advisory, consulting and corporate finance — with €104 million revenue in Spain and 1,100+ staff in 15 offices (2,500+ people and 62 offices worldwide). Founded and chaired by Mario Alonso Ayala, it sells an integrated "Big Four-style" service portfolio to mid-market companies with a "humanist, close-to-client" culture, plus standout niches in forensic/expert-witness work, public-sector audit and M&A. In March 2025, Dutch private...
Recent mention · Ransomware.live
🏴☠️ Thegentlemen has just published a new victim : Drinks Wines SpiritsRansomware.live · 30 Sep 2026
drinks.com.tw zoominfo.com/c/drinks-wines--spirits-co-ltd/425924055 DRINKS / Oak Barrel (橡木桶洋酒, Drinks Wines & Spirits Co., Ltd.) (founded 1993, Taipei) is Taiwan's largest liquor retail and import chain — 33–35 stores nationwide with about NT$2 billion (US$60M) annual revenue and 200–300 staff. Founded by "godfather of imported liquor" Chen Chun-an (died February 2026 at 80), it pioneered the wine-tasting culture in Taiwan through its Wine Party magazine, six tasting classrooms and a discount-store format with near-franchise store-manager economics. Beyond retail, it holds exclusive Taiwan...
Recent mention · Ransomware.live
🏴☠️ Incransom has just published a new victim : bcx.co.zaRansomware.live · 29 Sep 2026
www.bcx.co.za BCX (Business Connexion) https://www.zoominfo.com/c/business-connexion-pty-ltd/372844609 Total leak: 500 GB 4,224,088 Files, 596,613 Folders The leak includes source code, technical documentation and other confidential information. Source code: 6 fully functional business applications 15+ integration libraries/modules 10+ test and utility projects BUSINESS APPLICATIONS 1) Cemetery Management / Cemres 2) mSCOA Posting Level Creator 3) SolarReceipting 4) PortalSSO / Solution_Menu 5) StopWatch Reports 6) ChangeRequestManager INTEGRATION PLATFORM 1....
Recent mention · Ransomware.live
🏴☠️ Qilin has just published a new victim : IslandRansomware.live · 27 Sep 2026
N/A
Recent mention · Ransomware.live
🏴☠️ Qilin has just published a new victim : Inversiones BolívarRansomware.live · 24 Sep 2026
N/A
Recent mention · SOCRadar
Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization PipelineSOCRadar · 24 Sep 2026
Operation Master: Deconstructing a Multi-Tiered Intrusion and Monetization Pipeline SOCRadar Threat Research Unit (STRU) has uncovered an end-to-end cybercrime operation dubbed Operation Master, in which a threat actor c
Recent mention · Ransomware.live
🏴☠️ Krybit has just published a new victim : www.jonesthegrocer.comRansomware.live · 24 Sep 2026
Jones the Grocer is a premium gourmet food retail and cafe brand founded in 1996 in Sydney, Australia, originally launch...
Recent mention · Ransomware.live
🏴☠️ Medusalocker has just published a new victim : SeznamRansomware.live · 23 Sep 2026
Organization with 115 emails extracted. Domain: seznam.cz
Recent mention · Ransomware.live
🏴☠️ Thegentlemen has just published a new victim : GrupoliderRansomware.live · 21 Sep 2026
grupolider-ao.com zoominfo.com/c/grupolider/429885445 Grupolider is an Angolan diversified holding company founded in 1999, headquartered in Catete (Luanda province). The group operates in agriculture, logistics, freight forwarding, construction, and furniture manufacturing, with its flagship business being Novagrolider — the largest agricultural producer in Angola. Novagrolider farms around 20,000 hectares of land and produces roughly 150,000 tons of food per year (bananas, vegetables, fruit, and dairy), while the group employs over 3,200 direct staff. The company exports to Portugal,...
Recent mention · Ransomware.live
🏴☠️ Lockbit5 has just published a new victim : hygear.comRansomware.live · 18 Sep 2026
yGear specializes in providing reliable and affordable on-site and on-demand hydrogen and industrial...
Recent mention · Ransomware.live
🏴☠️ Ransomhouse has just published a new victim : PertaminaRansomware.live · 17 Sep 2026
Pertamina is an energy company primarily in the oil and gas sector. The company provides services for new and renewable energy, and other activities related to or supporting business activities in energy.
Recent mention · Ransomware.live
🏴☠️ Interlock has just published a new victim : City of Fort Smith ArkansasRansomware.live · 15 Sep 2026
The City of Fort Smith is committed to providing high-quality, resident-focused services to foster a thriving community. This is how they try to position themselves, but in reality, they are very negligent towards their residents and organizations within the city due to their negligent attitude towards security and lack of desire to solve problems, were compromised resulting in a major leak of confidential data over 5.6 TB of data, which includes key infrastructure facilities of Fort Smith (Public Safety System: Police Station, Fire Department, Communications Center (responsible for the 911...
Recent mention · Ransomware.live
🏴☠️ Thegentlemen has just published a new victim : SomitRansomware.live · 15 Sep 2026
somit.com zoominfo.com/c/somit/372548242 Guatemalan IT systems integrator founded in 1994 — designing, deploying and maintaining data networks, telecommunications, security systems, data-center engineering (power/cooling) and telemedicine & distance-learning interactive platforms for Guatemala's corporate and government sectors. In-house certified engineering staff; anchor clients include banks, universities and government institutions. A classic invisible Central-American integrator: 30+ years in the market, stable demand from banks and the state, near-zero international digital footprint
Recent mention · Ransomware.live
🏴☠️ Doommageddon has just published a new victim : INCOR GroupRansomware.live · 13 Sep 2026
Status: upcoming | Data size: — | Files: 0 files | Deadline: 2026-09-20T00:00:00Z
Recent mention · Ransomware.live
🏴☠️ Krybit has just published a new victim : www.ibnsinatrust.comRansomware.live · 12 Sep 2026
The Ibn Sina Trust is a pioneering Bangladeshi non-profit welfare trust and major healthcare provider founded on June 30...
Recent mention · Ransomware.live
🏴☠️ Krybit has just published a new victim : lasultanahotels.comRansomware.live · 12 Sep 2026
La Sultana Hotel Group is a Moroccan luxury boutique hotel group created in the year 2000, targeting discerning traveler...
Recent mention · Tenable Blog
CVE-2025-32756: Zero-Day Vulnerability in Multiple Fortinet Products Exploited in the WildTenable Blog · 14 May 2025
Fortinet has observed threat actors exploiting CVE-2025-32756, a critical zero-day arbitrary code execution vulnerability which affects multiple Fortinet products including FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera.BackgroundOn May 13th, Fortinet published a security advisory (FG-IR-25-254) for CVE-2025-32756, a critical arbitrary code execution vulnerability affecting multiple Fortinet products.CVEDescriptionCVSSv3CVE-2025-32756An arbitrary code execution vulnerability in FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera9.6AnalysisCVE-2025-32756 is an...
These PoCs are unverified and could contain malware. Use at your own risk.
nuclei · Created Unknown
metasploit · Created Unknown
Metasploit module for CVE-2022-40684
Timeline
04:30 UTC
Exploitation attested by an external source
00:00 UTC
Exploitation attested by an external source
15:02 UTC
Exploit module available
15:02 UTC
Public proof-of-concept code published
00:00 UTC
Scanner coverage available
00:00 UTC
Vulnerability disclosed publicly
00:00 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
00:00 UTC
Exploit observed in malware
00:00 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2022-40684
Free JSON includes basic KEV fields{
"cve_id": "CVE-2022-40684",
"confidence": "Confirmed",
"cvss_score": 9.8,
"cvss_estimated": false,
"epss_score": 0.99984,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}