Fortinet fixes critical zero-day exploited in FortiVoice attacks
ID: 4bf8a5a1-42db-55be-be3a-7bc917f3bb48
STIX ID: report--4bf8a5a1-42db-55be-be3a-7bc917f3bb48
Feed Name: Bleeping Computer
Fortinet released patches for a critical, actively exploited zero-day (CVE-2025-32756) affecting FortiVoice and other Fortinet products that permits unauthenticated remote code execution via malicious HTTP requests; observed attack activity included specific attacker IPs, fcgi debugging being enabled on compromised systems, malware drops, credential-harvesting cron jobs, and network-scanning scripts, with mitigation recommending immediate patching or disabling HTTP/HTTPS admin access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
