Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks
ID: 5540077f-bfb5-5ffe-a39b-c468107ce901
STIX ID: report--5540077f-bfb5-5ffe-a39b-c468107ce901
Feed Name: cybersecurityNews.com
A critical unauthenticated OS command injection (CVE-2025-64155) in Fortinet FortiSIEM's phMonitor service enables remote code execution on Super/Worker nodes; proof-of-concept exploit code is public and Defused observed active exploitation against honeypots with embedded second-stage infrastructure. The report lists affected versions, recommended fixed releases, sample payload patterns, observables (several IPs/ASNs), and interim mitigations (block TCP 7900, monitor phMonitor logs, upgrade affected nodes).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
