logo

Fortinet SIEM issue coincides with spike in brute-force traffic against company’s SSL VPNs

ID: 77774018-c492-5496-b90b-cc398c82014f

STIX ID: report--77774018-c492-5496-b90b-cc398c82014f

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2025-08-13

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Fortinet disclosed a critical OS command injection vulnerability (CVE-2025-25256, CVSS 9.8) in FortiSIEM with practical exploit code reported in the wild; Fortinet advises upgrading affected versions and restricting access to port 7900. GreyNoise reported a significant spike in brute-force activity targeting Fortinet SSL VPNs (hundreds of unique IPs and dozens of malicious sources), raising concern that public exploit code could accelerate exploitation given past widespread abuse of Fortinet defects.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.