Hello everybody. If you use FortiManager from FortiNet you should be prepared to grab the latest available release from the support portal and upgrade.

Patches aren’t out yet. Mitigation is available. If you have FortiManager facing the internet, I’d say remove it from the internet now. #threatintel https://mastodon.green/@fthy/113299522822025433

fthy (@[email protected])

Patch your FortiManager now. Limit access to it to only from dedicated jump-servers. #fortinet #fortimanager #infosec

Mastodon.green
@GossiTheDog Shouldn't FortiManager the typical kind of software which should be reachable only for an internal administrative vlan, and in peticular never be exposed on internet in first place ?
@ck0 @GossiTheDog I would say: never face any management to the internetsite. I wonder always when i read that vcenter are reachable from the internet. That must be really lazy admins here.