0-Day Pre-Auth SSRF Exploit for FortiGate 8.0.0 for Sale
Dark Web2026-08-11, 09:25
0-Day Pre-Auth SSRF Exploit for FortiGate 8.0.0 for Sale
For informational purposes only.
Affected version: FortiGate 8.0.0
Vulnerability type: Pre-auth SSRF
Price: $25к
The seller claims to be offering a 0-day SSRF vulnerability affecting FortiGate 8.0.0. According to the post, exploitation does not require prior authentication and allows an attacker to force the FortiGate device to make arbitrary network requests on the attacker's behalf.
The seller specifically states that requests can also be directed at resources that are only accessible from the internal network. This could potentially allow a vulnerable device to be used as a pivot point for reaching internal services that are not directly exposed to the internet.
The package is said to include both a scanner for identifying potentially vulnerable devices and the exploit itself.
FortiGate is Fortinet's line of next-generation firewalls, widely used by organizations to protect corporate networks, provide VPN access, filter traffic, and segment internal infrastructure.
Vendors
Products