Fortinet Products Are in the Crosshairs Again
ID: b8002396-8864-5f73-9b81-e86b55f06f06
STIX ID: report--b8002396-8864-5f73-9b81-e86b55f06f06
Feed Name: Dark Reading
Fortinet disclosed a critical unauthenticated OS command injection vulnerability (CVE-2025-25256) in FortiSIEM (versions 5.4 through 7.3.1) that allows remote code execution; proof-of-concept exploit code is circulating and Fortinet has released fixes and recommended limiting access to the phMonitor port (7900). GreyNoise observed a significant spike in targeted brute-force activity against Fortinet SSL VPNs and a second wave focusing on FortiManager via FGFM, suggesting attackers may be pivoting to breach centralized management to scale access; the flaw produces no distinctive IOCs, increasing detection difficulty.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
