Fortinet warns of new FortiWeb zero-day exploited in attacks
ID: 8f42ef1f-88f6-5857-95b6-6d50ef8b0a23
STIX ID: report--8f42ef1f-88f6-5857-95b6-6d50ef8b0a23
Feed Name: Bleeping Computer
Fortinet released emergency patches for a FortiWeb zero-day (CVE-2025-58034) actively exploited in the wild that allows authenticated attackers to perform OS command injection and execute code via crafted HTTP requests or CLI commands; Trend Micro and Fortinet observed exploitation (~2,000 detections reported), and administrators are urged to upgrade affected FortiWeb versions to the listed patched releases. The advisory also references other recently exploited FortiWeb zero-days (e.g., CVE-2025-64446) and related mitigations and agency actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
