View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA

๐Ÿšจ ACTIVE EXPLOITATION

  • Gunra Ransomware Exploits Fortinet VPN Flaws to Bypass MFA Gunra ransomware affiliates are exploiting Fortinet VPN flaws to breach organizations.
    • Government, critical infrastructure, healthcare, financial services, manufacturing, transportation, and other sectors are targeted.
    • Gunra exploits Fortinet vulnerabilities CVE-2024-55591 and CVE-2025-24472 in internet-facing firewall and VPN appliances.
    • Actors tamper with VPN or VDI authentication files to bypass MFA and gain privileged access.
    • Impacket tools support SMB lateral movement, credential dumping, pass-the-hash, and pass-the-ticket attacks.
    • Gunra exfiltrates enterprise data before encrypting files with ChaCha20 and RSA-4096, appending .ENCRT and dropping R3ADM3.txt. ๐Ÿ“Ž Coverage: cryptika.com ยท ๐Ÿ‘ via cryptika.com (discovered)

๐Ÿ”“ CVEs & KEV

  • CVE-2026-72902 โ€” CVSS 9.9 โ€” Dokploy: Authenticated RCE via Command Injection in registry.testRegistry / r...
  • CVE-2026-72901 โ€” CVSS 9.9 โ€” Dokploy: Remote Code Execution via volume-backupDokploy is a free, self-hosta...
  • CVE-2026-72886 โ€” CVSS 9.9 โ€” Dokploy: Non-admin member gains root on the host by bypassing the owner/admin...
  • CVE-2026-72882 โ€” CVSS 9.9 โ€” Dokploy: Authenticated blind command injection via file mounts leads to direc...
  • CVE-2026-72872 โ€” CVSS 9.9 โ€” Dokploy Critical RCE via Unvalidated Bitbucket Configuration (CVE-2026-72872)
  • CVE-2025-15681 โ€” CVSS 9.2 โ€” Insufficient Webserver AuthenticationTBEA TLogger V2.1.0.0B0.0.0.0 contains a...
  • CVE-2025-15683 โ€” CVSS 8.8 โ€” Multiple Unauthenticated Denial-of-Service ConditionsTBEA TLogger V2.1.0.0B0....
  • CVE-2026-72883 โ€” CVSS 8.8 โ€” Dokploy: WebSocket Terminal Missing Service-Level Access ControlDokploy is a ...
  • CVE-2026-69118 โ€” CVSS 8.7 โ€” Cachet 2.4.1 Authenticated Server-Side Template Injection RCECachet through 2...
  • CVE-2025-15682 โ€” CVSS 8.7 โ€” Unauthenticated Resource ExhaustionTBEA TLogger V2.1.0.0B0.0.0.0 contains an ...
  • CVE-2026-72884 โ€” CVSS 8.7 โ€” Dokploy: Command Injection via Compose Custom CommandDokploy is a free, self-...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check