logo

Fortinet fixes critical zero-day exploited in FortiVoice attacks

ID: 4bf8a5a1-42db-55be-be3a-7bc917f3bb48

STIX ID: report--4bf8a5a1-42db-55be-be3a-7bc917f3bb48

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-05-13

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Fortinet released patches for a critical, actively exploited zero-day (CVE-2025-32756) affecting FortiVoice and other Fortinet products that permits unauthenticated remote code execution via malicious HTTP requests; observed attack activity included specific attacker IPs, fcgi debugging being enabled on compromised systems, malware drops, credential-harvesting cron jobs, and network-scanning scripts, with mitigation recommending immediate patching or disabling HTTP/HTTPS admin access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.