The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check your FortiMonitorOnSight version; confirm whether it is 7.2.0–7.2.7.
If you are on 7.2.0–7.2.7, plan an immediate upgrade to FortiMonitorOnSight 7.2.8 or above.
After upgrading, verify the service is running normally and that configuration/backups still apply as expected.
If you cannot upgrade right away, restrict network access to FortiMonitorOnSight so it is not reachable from untrusted networks, and open a support ticket to get an official workaround/ETA.
A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>
In plain language
Written by AI from the record
FortiMonitorOnSight (versions 7.2.0–7.2.7) has a network-access flaw that lets an attacker break in without any login, including reading and changing sensitive data and disrupting service—so most small businesses running it should treat this as an urgent patch.
Fortinet FortiMonitorOnSight has an unauthenticated network access control flaw (CWE-540) that can expose sensitive information and enable remote attackers to read/modify/delete critical data and disrupt services without credentials; fix by upgrading to FortiMonitorOnSight 7.2.8+.
If you're affected
Full system data exposure
Data tampering or deletion
Monitoring/service disruption
Possible operational downtime
What is it
Think of FortiMonitorOnSight as the guardhouse that watches what’s happening on your network. This bug accidentally puts sensitive “inside information” where outsiders can reach it over the network, letting them potentially take control of important data and even knock the service offline—without needing a username or password.
Who is affected
This matters if your business uses Fortinet FortiMonitorOnSight in the affected version range (7.2.0 through 7.2.7) and that system can be reached over the network. The findings describe no login requirement, meaning the biggest risk is exposure from the network to an attacker. If FortiMonitorOnSight is not reachable from untrusted networks, the risk is reduced—but you should still patch because exposure requirements are not fully known.
How urgent is it
This is RED because attackers don’t need any login—so if your FortiMonitorOnSight is reachable from the network, exploitation would be straightforward. Even though no confirmed “in-the-wild” exploitation is reported in the findings, the impact described includes reading, modifying, and deleting critical data and disrupting services, which makes this patch urgent.
What to do — in detail
Confirm exposure and version
Log into your FortiMonitorOnSight admin interface (or use your device management tooling) and record the exact FortiMonitorOnSight version.
Determine whether the management/monitoring interfaces are reachable from untrusted networks (e.g., the public internet, partner networks, or any network segment not fully controlled by you).
Confirm whether you’re in the vulnerable range
If your version is FortiMonitorOnSight 7.2.0 through 7.2.7, you are within the affected range described by the findings.
Apply the fix
Upgrade to FortiMonitorOnSight 7.2.8 or above (this is the vendor remediation stated in the findings).
During/after the upgrade: verify the service is up, normal dashboards/monitoring functions work, and no unexpected configuration changes occurred.
If patching is delayed
Immediately restrict network access so the system is not reachable from untrusted sources (for example: block inbound from the internet and any non-essential networks; allow only required internal IP ranges).
Contact Fortinet support (or your vendor) to request an official interim workaround and guidance specific to your deployment.
What to monitor
Review FortiMonitorOnSight-related logs for unusual access patterns, unexpected configuration/data changes, and service disruptions—especially after any network changes or around the time you suspect scanning activity.
KEV / exploitation status
CISA KEV does not list this issue in the findings, and no dated in-the-wild exploitation report was provided. Even so, the findings describe a no-auth network attack path with high impact, so prioritize upgrading rather than waiting.
Technical context
Severity is effectively critical for the described environment because the flaw enables unauthorized actions without credentials. The underlying weakness is a mishandling of source-code handling leading to sensitive information exposure and improper access control (CWE-540). The findings state: attack vector is network, authentication required is none, and user interaction is not required. KEV is not listed for this CVE in the findings, and there is no public exploit code on record; press reporting did not provide a clear dated claim of exploitation. However, the traffic-light verdict for this CVE is RED. Vendor remediation is available via upgrade to FortiMonitorOnSight 7.2.8 or above. (EPSS is provided in the findings as a prediction, but public blocks should not rely on it given the chosen urgency based on impact and attack path described.)
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.