logo

New Fortinet FortiWeb hacks likely linked to public RCE exploits

ID: b84ff219-8213-5a95-bceb-bddf86771cf8

STIX ID: report--b84ff219-8213-5a95-bceb-bddf86771cf8

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-07-16

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Multiple Fortinet FortiWeb appliances are being actively exploited via a critical pre-auth SQL injection RCE (CVE-2025-25257) after public exploit code was released; Shadowserver observed dozens of web shell infections and reported hundreds of exposed management interfaces. Fortinet published patches (upgrade to 7.6.4, 7.4.8, 7.2.11, or 7.0.11+) and recommends immediate updates or disabling the HTTP/HTTPS administrative interface to mitigate further compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.