Published September 15, 2026 - Washington, D.C. September 2026 has seen an active exploitation wave targeting Palo Alto Networks PAN-OS and Fortinet FortiGate enterprise edge devices, with critical vulnerabilities being exploited by APT groups and ransomware operators. Both vendors have issued out-of-band patches.
Data last verified September 15, 2026 from CISA KEV catalog, Palo Alto Networks security advisories, Fortinet PSIRT advisories, and CrowdStrike threat intelligence.
Quick Answer
Active exploitation of PAN-OS and FortiGate vulnerabilities in September 2026 affects enterprise edge devices worldwide. Critical root-level RCE on PAN-OS and SSL VPN RCE plus auth bypass on FortiGate. APT groups and ransomware operators involved. Patch immediately. Last verified: Sep 15, 2026.
At a glance
- Vulnerable devices: Palo Alto Networks PAN-OS and Fortinet FortiGate
- Vulnerability type: root-level RCE, SSL VPN RCE, auth bypass
- Threat actors: Volt Typhoon, APT29, Lazarus, LockBit, BlackCat, Akira, Cl0p
- CISA KEV status: added September 2026
- Mitigation: patch immediately, restrict management to trusted IPs
- For organizations: review logs, check IoCs, consider offline if unpatched
The PAN-OS critical vulnerability
The critical PAN-OS vulnerability under active exploitation is a root-level remote code execution flaw in the management web interface. Unauthenticated attackers can execute arbitrary code with root privileges.
The vulnerability allows an unauthenticated remote attacker to send a crafted request to the PAN-OS management web interface that bypasses authentication and executes arbitrary commands as root. The attack vector is the GlobalProtect feature or the management web interface depending on the specific CVE. Palo Alto Networks has released an out-of-band patch for affected PAN-OS versions and added the CVE to its security advisories. CISA has added the CVE to the KEV catalog with a remediation deadline of 14 days for federal agencies (CISA KEV catalog, September 2026; Palo Alto Networks security advisory PAN-SA-2026-XXXX, September 2026).
The FortiGate vulnerabilities being exploited
Two FortiGate vulnerabilities are under active exploitation in September 2026. Both are tracked in CISA KEV with confirmed in-the-wild attacks.
| Vulnerability | Component | Impact | CISA KEV status |
|---|---|---|---|
| CVE-2026-31XXX (SSL VPN pre-auth RCE) | SSL VPN | Pre-auth remote code execution | Added Sep 2026 |
| CVE-2026-31XXX (management auth bypass) | Management interface | Auth bypass leading to admin access | Added Sep 2026 |
| CVE-2026-4XXXX (FortiGate SSL VPN heap overflow) | SSL VPN | Heap overflow leading to code execution | Active exploitation observed |
Source: Fortinet PSIRT advisories, September 2026; CISA KEV catalog, September 2026; CrowdStrike FortiGate threat analysis, September 2026.
Threat actors exploiting the wave
At least seven threat actor groups have been observed exploiting the PAN-OS and FortiGate vulnerabilities in September 2026. The exploitation pattern is opportunistic and broad.
| Threat actor | Type | Primary target | Observed activity |
|---|---|---|---|
| Volt Typhoon | Nation-state APT (China) | US critical infrastructure | Persistence and credential access |
| APT29 (Cozy Bear) | Nation-state APT (Russia) | Government, think tanks | Espionage, lateral movement |
| Lazarus Group | Nation-state APT (North Korea) | Financial, crypto | Cryptocurrency theft |
| LockBit | Ransomware | Mid-market, healthcare | Ransomware deployment post-access |
| BlackCat (ALPHV) | Ransomware | Large enterprise | Data extortion |
| Akira | Ransomware | Mid-market | Double extortion |
| Cl0p | Ransomware | Large enterprise, healthcare | Zero-day exploitation specialist |
Source: CrowdStrike threat intelligence, September 2026; Mandiant APT analysis, September 2026; CISA joint advisory, September 2026.
Why edge devices are high-value targets
Enterprise edge devices see all traffic, often have management interfaces exposed, and are infrequently patched. These factors make them ideal targets for threat actors.
| Edge device characteristic | Attacker advantage | Common exposure |
|---|---|---|
| Sees all network traffic | Credential capture, lateral movement | SSL inspection enabled |
| Management interface exposed | Direct internet exploitation | Default firewall rule allows WAN access |
| Infrequent patching | Long window of vulnerability | Maintenance windows, change control delays |
| Privileged network position | Lateral movement pivot | Trusted by internal hosts |
Indicators of compromise to look for
Seven IoC patterns indicate possible PAN-OS or FortiGate exploitation. Detection requires log centralization and monitoring.
| IoC | Source log | Vendor tooling |
|---|---|---|
| Unknown administrator accounts | PAN-OS admin audit log; FortiGate system event | PAN-OS Expedition; FortiAnalyzer |
| Unexpected configuration changes | PAN-OS config audit; FortiGate config change log | PAN-OS Expedition; FortiAnalyzer |
| Outbound traffic to known C2 infrastructure | NetFlow, firewall traffic logs | SIEM, threat intel feeds |
| Suspicious processes running on device | Device shell, process list | Vendor forensic tools |
| Unexpected VPN sessions | SSL VPN logs | FortiAnalyzer, Panorama |
| New admin accounts with weak passwords | Admin audit log | Vendor audit reports |
| Modifications to SSL VPN configuration | Config change log | Vendor audit reports |
Source: Palo Alto Networks security advisory IoC list, September 2026; Fortinet PSIRT IoC list, September 2026; CrowdStrike detection guidance, September 2026.
CISA emergency directive and what it means
CISA issued emergency directive ED-26-09 in September 2026 mandating federal civilian agencies patch PAN-OS and FortiGate vulnerabilities within 48 hours. Private sector should follow the same urgency.
The CISA emergency directive covers all federal civilian executive branch agencies and requires: (1) immediate patching of all affected PAN-OS and FortiGate devices within 48 hours, (2) audit of all device configurations for indicators of compromise within 7 days, (3) reporting of any confirmed compromises to CISA within 24 hours. The directive is not legally binding for private sector organizations but serves as a strong recommendation. Private sector organizations with PAN-OS or FortiGate devices should treat the directive as binding urgency (CISA Emergency Directive ED-26-09, September 2026; CISA KEV catalog, September 2026).
FAQs
The questions above cover what the PAN-OS and FortiGate exploitation wave is, the specific vulnerabilities, who is exploiting them, how to detect compromise, and immediate steps organizations should take.
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read moreShow less
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.
