logo

CISA gives govt agencies 7 days to patch new Fortinet flaw

ID: 53012b87-d71b-5068-ac95-a1233a90dd9f

STIX ID: report--53012b87-d71b-5068-ac95-a1233a90dd9f

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-11-19

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

CISA has ordered U.S. federal agencies to urgently patch Fortinet FortiWeb (CVE-2025-58034), an authenticated OS command injection that can allow root-level code execution via crafted HTTP/CLI requests; the flaw is actively exploited in the wild, was reported by Trend Micro, and was added to CISA's Known Exploited Vulnerabilities catalog with a one-week remediation deadline. The report also notes a related FortiWeb zero-day (CVE-2025-64446) and prior Fortinet vulnerabilities used in espionage and ransomware campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.