logo

CVE-2025-64155: FortiSIEM Remote Unauthenticated Command Injection Vulnerability

ID: 00c00c51-c066-5cd9-bd1e-32d47d8e9fbc

STIX ID: report--00c00c51-c066-5cd9-bd1e-32d47d8e9fbc

Feed Name: Arctic Wolf

Threat Score
75/100

Date Published: 2026-01-15

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

**Executive summary:** Fortinet released fixes for CVE-2025-64155, a critical unauthenticated command-injection vulnerability in FortiSIEM's phMonitor (TCP/7900) that can enable remote code execution, file write of reverse shells, and escalation from admin to root; a public PoC exists though Arctic Wolf has not observed in-the-wild exploitation. The advisory recommends immediate upgrades to listed fixed versions, isolating FortiSIEM from the internet, and restricting access to TCP/7900 as interim mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.