981,494 FortiGate Fingerprints and 16.4 Million RDP Services: Measuring the Gunra Initial-Access Surface
The August 2026 joint advisory on Gunra ransomware describes an intrusion chain that starts with two known Fortinet vulnerabilities, CVE-2024-55591 and CVE-2025-24472, and continues with weak VPN credentials and brute-forced RDP. Both vulnerabilities are in the CISA KEV catalog, which means they were already being exploited before Gunra campaigns were attributed to them.
That makes the Gunra advisory a useful case for exposure measurement. The initial-access path is documented, so the question is how large the reachable population is.
What the queries show
A ZoomEye query for app="FortiGate" returns 981,494 fingerprint matches. A query for service="rdp" returns 16,449,359.
The FortiGate figure is a product fingerprint count. It identifies devices that ZoomEye recognizes as FortiGate, which is the product family affected by the two CVEs named in the advisory. It does not indicate firmware version, patch level, or whether the specific vulnerable component is enabled. A device counted here may be fully patched.
The RDP figure is broader still. It counts exposed Remote Desktop services across all operating systems and configurations. The advisory describes brute-force RDP as one of several access methods, not the only one.
Reading the two numbers together
The two counts describe different parts of the same problem. The FortiGate population is the documented vulnerability path: devices that an attacker can target with a specific exploit. The RDP population is the credential path: services that an attacker can target with password guessing and reused credentials.
The advisory's mitigation list reflects both. Its first recommendation is to patch known exploited vulnerabilities on internet-facing systems, including VPN gateways and RDP-exposed infrastructure. That phrasing treats the two as a single category, which is the right way to read the measurement.
Neither count tells you which devices are unpatched. The FortiGate fingerprint does not expose firmware version, and RDP does not advertise whether Network Level Authentication is enforced or whether accounts are locked out after failed attempts.
Why the numbers still matter
A count of 981,494 FortiGate devices establishes that the affected product family is widely deployed on the public internet. When a vulnerability in that family reaches the KEV catalog, the population that needs to verify its patch state is large enough that the work has to be planned rather than improvised.
The 16.4 million RDP services matter for a different reason. RDP exposure is a standing condition, not an event. Every organization that exposes it has to assume credential attacks are continuous, which is why the advisory pairs patching with credential hygiene.
What to verify internally
- Confirm the firmware version on every FortiGate device that faces the internet, and compare it against the fixed release for CVE-2024-55591 and CVE-2025-24472.
- Audit VPN credentials for reuse and age. The advisory names weak and reused credentials alongside the vulnerabilities.
- Check whether RDP is exposed directly to the internet, and whether account lockout and network-level authentication are enforced.
- Treat MFA configuration files on remote-access servers as integrity-monitored assets. The advisory documents a server-side MFA bypass through modification of those files.
References
- ZoomEye,
app="FortiGate", 981,494 matches, queried 20 September 2026. - ZoomEye,
service="rdp", 16,449,359 matches, queried 20 September 2026. - FBI, CISA, NSA, DC3, USSS and KNPA, "#StopRansomware: Gunra Ransomware," AA26-222A, 10 August 2026. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a
- CISA Known Exploited Vulnerabilities catalog entries for CVE-2024-55591 and CVE-2025-24472.
Top comments (0)