logo

Critical FortiSIEM Vulnerability(CVE-2025-64155) Enable Full RCE and Root Compromise

ID: d41b9db2-79c1-588a-bbfa-c38d33eecb21

STIX ID: report--d41b9db2-79c1-588a-bbfa-c38d33eecb21

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-01-14

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Fortinet FortiSIEM is affected by an unauthenticated OS command injection (CVE-2025-64155/CVE-2025-25256) that allows attackers to inject arguments into a curl-based script to overwrite binaries (e.g., phLicenseTool) and obtain admin shells; those admin shells can then escalate to root by overwriting a writable root cron job. A public proof-of-concept exploit is available, practical exploitation was observed, and threat actors (including mentions in leaked Black Basta chats) have shown interest; Fortinet has released patches and advises upgrades and port 7900 restrictions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.