Alert: Unpatched Fortinet Devices Fall to Gunra Ransomware
U.S. and South Korean agencies warned that the Gunra ransomware group is targeting unpatched VPN gateways and firewall appliances for initial access. The alert says two Fortinet vulnerabilities in FortiOS and FortiProxy (CVE-2025-24472 and CVE-2024-55591) can enable authentication bypass and super-admin privileges. The FBI said exfiltrated data includes PII and internal emails.
How this was made
The 30-second read
Why it matters
The key new element for markets is the explicit linkage of Gunra’s active initial-access method to Fortinet’s FortiOS and FortiProxy authentication-bypass vulnerabilities (CVE-2025-24472 and CVE-2024-55591), with potential for super-admin access and persistent remote access via SSL VPN tunnels.
Market read
This is a direct, actionable cyber-risk alert for Fortinet’s internet-facing edge security stack, but it lacks financial metrics or Fortinet-specific corporate actions.
What to watch
Traders may overestimate equity impact; the more immediate tradable effect could be on incident-response vendors, managed security providers, and customers’ near-term capex for network hardening rather than on Fortinet’s core revenue.
Background
A joint US and South Korea cybersecurity alert warns the Gunra ransomware-as-a-service operation is targeting unpatched VPN gateways and firewall appliances, including Fortinet products.
Ticker impact
The alert says Gunra is exploiting two Fortinet flaws in FortiOS and FortiProxy to gain super-admin access and establish SSL VPN tunnels.
Near-term equity impact is likely limited unless follow-on disclosures emerge (large customer incidents, guidance changes, or material remediation costs).
The article is a government-backed threat alert tied to specific Fortinet products and CVEs, which can raise perceived cyber-risk and remediation urgency, but it does not provide financial figures or new Fortinet corporate actions.
Market effects
May increase near-term demand for patching, segmentation, and incident-response services across network security and critical-infrastructure IT.
US and South Korea coordination highlights heightened scrutiny and faster patch cycles in both regions’ critical sectors.
The advisory frames a worldwide victim footprint across healthcare, finance, manufacturing, transport, and government services.
Counterpoint
Because Fortinet issued patches in early 2025 and the advisory largely reiterates known CVE remediation, the incremental market impact may be muted versus already-priced cyber-risk.
Key entities
- companyFortinet
Vendor whose FortiOS and FortiProxy products are cited as being actively exploited for initial access by Gunra.
- threat_actorGunra ransomware
Ransomware-as-a-service operation using VPN/firewall exploitation for initial access and data exfiltration.
- government_agenciesCISA, FBI, NSA, Secret Service
US agencies issuing the joint alert warning organizations to patch and mitigate lateral movement.
- government_agencyNational Police Agency (South Korea)
South Korean partner agency in the joint alert tying activity to unpatched edge devices.
- cybersecurity_firmAhnLab
South Korean firm supplementing the alert and noting it cannot definitively determine links between Gunra and Lazarus clusters.

