Fortinet Woes Continue With Another WAF Zero-Day Flaw
ID: bef40aed-b804-55f5-b88c-e67bdacf538c
STIX ID: report--bef40aed-b804-55f5-b88c-e67bdacf538c
Feed Name: Dark Reading
Fortinet disclosed CVE-2025-58034, an authenticated OS command injection in FortiWeb (CVSS 6.7) that is being exploited in the wild and may be chained with a recently disclosed FortiWeb zero-day (CVE-2025-64446). Researchers (Trend Micro, Rapid7) and Orange Cyberdefense report active exploitation campaigns and thousands of detections; CISA added CVE-2025-58034 to its Known Exploited Vulnerabilities catalog and urged rapid patching. Organizations are advised to update FortiWeb to patched versions and avoid exposing management interfaces while monitoring for suspicious account creation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
