Gunra Ransomware Exploits Fortinet Flaws, FBI Warns
FBI, CISA, and South Korea warn Gunra ransomware is exploiting two KEV-listed Fortinet firewall flaws to hit healthcare, finance, and critical infrastructure.
The FBI, CISA, and South Korea’s National Police Agency published a joint advisory Monday identifying Gunra as an active ransomware threat to critical infrastructure — a group that has moved from leaked source code to a ransomware-as-a-service operation in just over a year, exploiting two well-known Fortinet firewall authentication bypasses to get inside its targets.
Both CVEs are on CISA’s Known Exploited Vulnerabilities catalog. Both have had patches available since early 2025. That detail is the part worth sitting with.
What Gunra Is
Gunra emerged in April 2025, built on source code leaked from the Conti ransomware operation — itself dismantled after an internal affiliate dispute went public in 2022. By January 2026, the group had transitioned to a ransomware-as-a-service model and began operating under an additional alias, “Golden Community,” as it expanded its targeting to critical infrastructure and industrial organizations.
The advisory documents twelve confirmed attacks in the first half of 2026: eight in Q1, four more in Q2. Targets span healthcare, financial services, and government sectors. Ransom demands exceeded $10 million in most cases, with payment windows of five to seven days.
The Entry Points
Gunra actors are entering networks through two Fortinet authentication bypass vulnerabilities:
CVE-2024-55591 — CVSS 9.8 (critical). An unauthenticated attacker can gain super-admin privileges in FortiOS and FortiProxy via crafted requests to the Node.js websocket module. Added to the CISA KEV catalog in January 2025, with a required remediation deadline of January 21, 2025 for federal agencies.
CVE-2025-24472 — CVSS 8.1 (high). A second Fortinet authentication bypass allowing an attacker to gain super-admin access via crafted CSF proxy requests. Added to KEV in March 2025.
Using months-old, KEV-listed perimeter vulnerabilities against high-value targets is a pattern ransomware operators return to because it keeps working. CISA flagged ransomware exploitation of SonicWall firewall CVEs just yesterday — same structure: ransomware gangs, critical infrastructure, firewall CVEs that have been patchable for months.
What to Check Now
If Fortinet devices are part of your perimeter:
- Confirm FortiOS and FortiProxy are patched against both CVEs — the KEV-required remediation dates have long since passed.
- Review firewall administrative logs for unexpected privilege escalation or new session creation, particularly for administrator-level accounts.
- Audit active administrator accounts against your known-authorized list; both CVEs enable creation of unauthorized super-admin accounts as an initial foothold.
The full advisory is available through CISA and includes affected product versions and additional TTPs.
Track actively exploited vulnerabilities on our KEV tracker.
- [ CRITICAL ] CVE-2024-55591 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
- [ HIGH ] CVE-2025-24472 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Found this useful? Share it.


