logo

Critical FortiSIEM Vulnerability Allows Attackers to Execute Malicious Commands, PoC Found in the Wild

ID: 1d3dbfab-997c-5dd9-bfa3-9350050c6b64

STIX ID: report--1d3dbfab-997c-5dd9-bfa3-9350050c6b64

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2025-08-13

Date Updated: 2026-04-22

Author: Divya

...
...

**Executive summary:** Security researchers disclosed CVE-2025-25256, a critical OS command injection in Fortinet FortiSIEM (CVSS 9.8) enabling unauthenticated remote command execution with exploit code observed in the wild; Fortinet published affected versions and remediation steps (upgrades or migration for older releases) and recommends immediate inventory, patching, and monitoring while using port 7900 access restrictions as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.