logo

Fortinet Products Are in the Crosshairs Again

ID: b8002396-8864-5f73-9b81-e86b55f06f06

STIX ID: report--b8002396-8864-5f73-9b81-e86b55f06f06

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-08-13

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Fortinet disclosed a critical unauthenticated OS command injection vulnerability (CVE-2025-25256) in FortiSIEM (versions 5.4 through 7.3.1) that allows remote code execution; proof-of-concept exploit code is circulating and Fortinet has released fixes and recommended limiting access to the phMonitor port (7900). GreyNoise observed a significant spike in targeted brute-force activity against Fortinet SSL VPNs and a second wave focusing on FortiManager via FGFM, suggesting attackers may be pivoting to breach centralized management to scale access; the flaw produces no distinctive IOCs, increasing detection difficulty.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.