Warning: OS command injection vulnerability in Fortinet FortiWeb, Patch Immediately!
ID: 06fc1515-7d83-50af-9ec3-0088ae2f5e1a
STIX ID: report--06fc1515-7d83-50af-9ec3-0088ae2f5e1a
Feed Name: CCB Advisories Feed
**Fortinet FortiWeb OS command injection (CVE-2025-58034)**: An authenticated OS command injection vulnerability affecting multiple FortiWeb versions (7.0.x–8.0.x) can allow execution of unauthorized code, enabling malicious traffic to bypass WAF protections; threat actors are actively exploiting this issue and chaining it with CVE-2025-64446 to escalate to unauthenticated remote code execution. The advisory (last updated 26/11/2025) strongly recommends patching, restricting HTTP/HTTPS management access, increasing monitoring, and investigating potential prior compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
