CVE-2019-5591

ENISA EUVD: EUVD-2019-15166 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 20, 2026 4 articles

EPSS Score

Source: FIRST.org · 2026-05-24
50.55%
probability
This CVE has a 50.55% probability of being exploited in the next 30 days.
0% Top 97.9th percentile of all CVEs 100%

CVSS v3.1

Source: NVD
6.5
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

Attack Intelligence

Exploits & PoC

ayewo/fortios-ldap-mitm-poc-CVE-2019-5591

The default configuration of LDAP on FortiOS v6.0.x to v6.2.0 does not check server identity for LDAP/S leading to MITM attacks. This PoC demos full e

1
1 repo — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
75%
EPSS 50.55%
CVSS v3.1 6.5
Mentions 4
Last Seen Aug 17, 2021

CNA Information

Analyst Note

BleepingComputer article explicitly labels CVE-2019-5591 as a 'zero-day allowing remote server takeover' with Fortinet delays in patching. TheHackerNews confirms an unpatched OS command injection in FortiWeb. The 2019 CVE year combined with contemporary reporting of active exploitation and delayed patches supports zero-day classification.

Threat Actors 4

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
APT 29
apt_group Information theft and espionage 🇷🇺 RU
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
APT42
apt_group Information theft and espionage 🇮🇷 IR

Triage Info

Decided atMar 20, 2026