Executive Summary
In early 2026, the Gunra ransomware group, a Ransomware-as-a-Service (RaaS) operation, exploited known vulnerabilities in Fortinet products, notably CVE-2026-24858, to bypass multi-factor authentication (MFA) and gain unauthorized access to critical infrastructure and government organizations worldwide. Utilizing the leaked Conti ransomware code, Gunra executed double-extortion attacks, encrypting data and threatening to publish stolen information unless ransoms were paid. The group's operations expanded through a structured affiliate program, targeting sectors such as healthcare, finance, manufacturing, transportation, and government services. (shellcodex.com)
This incident underscores the persistent threat posed by ransomware groups leveraging known vulnerabilities and the importance of timely patching and robust security measures. The exploitation of Fortinet flaws highlights the need for organizations to prioritize vulnerability management and implement comprehensive security protocols to mitigate such risks. (sentinelone.com)
Why This Matters Now
The Gunra ransomware attacks highlight the critical need for organizations to promptly address known vulnerabilities, especially in widely used security appliances like Fortinet's. The exploitation of these flaws to bypass MFA and execute double-extortion tactics emphasizes the evolving sophistication of ransomware groups and the importance of comprehensive security measures to protect sensitive data and infrastructure. (shellcodex.com)
Attack Path Analysis
Gunra ransomware actors exploited known vulnerabilities in Fortinet appliances to gain initial access, escalated privileges by modifying authentication processes, moved laterally by compromising identity and access management infrastructure, established command and control through persistent access mechanisms, exfiltrated sensitive data prior to encryption, and impacted organizations by deploying ransomware and deleting backups.
Kill Chain Progression
Initial Compromise
Description
Exploited known vulnerabilities in Fortinet appliances (CVE-2024-55591 and CVE-2025-24472) to gain unauthorized access.
Related CVEs
CVE-2024-55591
CVSS 9.8An authentication bypass vulnerability in FortiOS and FortiProxy allows remote attackers to gain super-admin privileges via crafted requests to the Node.js websocket module.
Affected Products:
Fortinet FortiOS – 7.0.0 through 7.0.16
Fortinet FortiProxy – 7.0.0 through 7.0.19, 7.2.0 through 7.2.12
Exploit Status:
exploited in the wildCVE-2025-24472
CVSS 8.1An authentication bypass vulnerability in FortiOS and FortiProxy allows remote attackers to gain unauthorized access via crafted requests.
Affected Products:
Fortinet FortiOS – 7.0.0 through 7.0.16
Fortinet FortiProxy – 7.0.0 through 7.0.19, 7.2.0 through 7.2.12
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Domain Accounts
Local Accounts
Cloud Accounts
Application Layer Protocol: Web Protocols
Application Layer Protocol: Web Protocols
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Management and Access Control
Control ID: Pillar 1: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Critical infrastructure targeting by Gunra RaaS exploiting Fortinet vulnerabilities threatens government services with ransomware deployment, backup deletion, and MFA bypass capabilities.
Health Care / Life Sciences
Healthcare organizations face severe ransomware exposure through VPN appliance exploitation, credential theft, and double-extortion attacks compromising patient data and operational continuity.
Financial Services
Banking and financial institutions vulnerable to authentication bypass attacks targeting SSL-VPN infrastructure, enabling lateral movement and data exfiltration through compromised access controls.
Transportation
Transportation sector infrastructure at risk from sophisticated RaaS operations exploiting network appliances, potentially disrupting logistics operations and critical transportation management systems.
Sources
- Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFAhttps://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfaVerified
- Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerabilityhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-55591Verified
- Fortinet Security Advisory FG-IR-24-535https://fortiguard.fortinet.com/psirt/FG-IR-24-535Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to exploit vulnerabilities, escalate privileges, move laterally, establish command and control, exfiltrate data, and deploy ransomware by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit known vulnerabilities in Fortinet appliances may have been constrained, reducing the likelihood of unauthorized access.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges by modifying authentication processes could have been limited, reducing unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network could have been restricted, limiting the spread of the attack.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish persistent command and control channels could have been limited, reducing sustained unauthorized access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data could have been restricted, reducing data loss.
The attacker's ability to deploy ransomware and delete backups could have been limited, reducing the overall impact of the attack.
Impact at a Glance
Affected Business Functions
- Network Security Operations
- Remote Access Services
- Data Backup and Recovery
Estimated downtime: 14 days
Estimated loss: $5,000,000
Potential exposure of sensitive corporate data and credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit lateral movement within the network.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing data exfiltration.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Deploy Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.
- • Regularly update and patch all systems, especially Internet-facing appliances, to mitigate known vulnerabilities.



