<- ALL CYBER NEWS
High
Gunra, Ransomware, Fortinet, FortiOS, FortiProxy, CVE-2024-55591, CISA

Gunra Ransomware Exploits Fortinet CVE-2024-55591
Gunra ransomware exploits Fortinet CVE-2024-55591 and CVE-2025-24472 for initial access. CISA advisory, EPSS, IOCs, and Fortinet hardening.
Gunra Ransomware Exploits Fortinet CVE-2024-55591 to Breach Networks
CISA and South Korean agencies have warned that Gunra ransomware is breaching organizations by exploiting internet-facing Fortinet FortiOS and FortiProxy flaws, CVE-2024-55591 and CVE-2025-24472, to gain initial access before deploying double-extortion ransomware. The lead flaw, CVE-2024-55591, is a CVSS 9.8 authentication bypass whose EPSS score sits at the 99.9th percentile, among the highest exploitation-likelihood ratings that exist. Gunra has targeted healthcare, financial services, and government sectors, and has listed 51 victims since emerging in April 2025. Patch FortiOS and FortiProxy and get management interfaces off the public internet now.
The pattern here is not novel, and that is exactly why it works. Gunra is using known, patchable Fortinet vulnerabilities rather than a fresh zero-day. CVE-2024-55591 (NVD, CVSS 9.8, CWE-288) is an authentication bypass that lets an attacker reach the appliance without valid credentials, and CVE-2025-24472 (CVSS 8.1) extends the same class of weakness. Both have been public and fixed for a while, which means every organization Gunra has breached through them had an available patch it had not applied to an internet-facing security appliance. The edge device meant to enforce the perimeter became the way through it.
Once inside, Gunra runs a double-extortion playbook: exfiltrate data, encrypt systems, and give victims five to seven days before publishing stolen files on a leak site. According to Ransomware.Live, its 51 listed victims skew toward South Korea, Brazil, Spain, Thailand, and Hong Kong, with only three reported from the United States and Canada so far, and phishing serves as a parallel delivery vector alongside the Fortinet exploitation. The joint advisory frames Gunra as one more entry in a steady trend of ransomware crews weaponizing edge appliances against critical-infrastructure sectors.
Why do ransomware crews keep entering through Fortinet edge devices?
Because a firewall or SSL-VPN sits at the perimeter, is reachable from the internet by design, and holds privileged position over everything behind it. That combination makes an unauthenticated appliance flaw the single most attractive initial-access vector for ransomware operators, and CVE-2024-55591's 99.9th-percentile EPSS reflects how aggressively this specific bug is being probed. The added risk in Fortinet estates is the Security Fabric: implicit trust between fabric members means breaching one node can open a path to others, so a single exposed appliance is rarely a contained problem.
What should defenders do about CVE-2024-55591 and CVE-2025-24472?
Patch both to fixed FortiOS and FortiProxy builds, and treat management-plane exposure as the real fix. Disable HTTP and HTTPS administrative access on WAN interfaces, restrict management to an out-of-band network or strict source-IP allowlists, and lock down Security Fabric synchronization ports to isolated internal VLANs. Then hunt for post-exploitation traces: unrecognized super_admin accounts created during the exploit window, unexpected SSH keys, and anomalies in configuration and session logs. Because the initial access relies on a bypass rather than credential theft, account and configuration auditing is where you confirm whether a patched box was already touched.
Detail | Value |
|---|---|
Actor | Gunra ransomware (active since April 2025) |
Exploited flaws | CVE-2024-55591 (9.8 auth bypass), CVE-2025-24472 (8.1) |
EPSS (CVE-2024-55591) | 99.9th percentile |
Model | Double extortion; 5 to 7 day leak-site deadline |
Sectors | Healthcare, financial services, government |
Victims | 51 listed (mostly South Korea, Brazil, Spain, Thailand, Hong Kong) |
Source | Joint CISA / South Korea advisory |
Our read
Continuous verification is the difference between owning a Fortinet appliance and being owned through one. Gunra is not defeating patched, hardened edge devices; it is finding the ones that were never updated or never taken off the public internet, which is a verification failure, not a sophistication problem. Our analysis of CISA's 2025 KEV data found that 67% of the year's actively exploited vulnerabilities would have been missed by an annual pentest, and an edge appliance carrying a 99.9th-percentile-EPSS auth bypass is precisely the asset that point-in-time testing overlooks between cycles. Patch these two CVEs, pull the management plane off the internet, and verify that exposure continuously, because ransomware crews are checking it continuously.
Reporting by The Hacker News; exploitation and victimology per the joint CISA and South Korea advisory, Ransomware.Live, and NVD. Sources linked above.
Related: Progress Kemp LoadMaster CVE-2026-8037 in CISA KEV · N-able N-central CVE-2026-18577 exploited in the wild