New Fortinet FortiWeb hacks likely linked to public RCE exploits
ID: b84ff219-8213-5a95-bceb-bddf86771cf8
STIX ID: report--b84ff219-8213-5a95-bceb-bddf86771cf8
Feed Name: Bleeping Computer
Threat Score
Multiple Fortinet FortiWeb appliances are being actively exploited via a critical pre-auth SQL injection RCE (CVE-2025-25257) after public exploit code was released; Shadowserver observed dozens of web shell infections and reported hundreds of exposed management interfaces. Fortinet published patches (upgrade to 7.6.4, 7.4.8, 7.2.11, or 7.0.11+) and recommends immediate updates or disabling the HTTP/HTTPS administrative interface to mitigate further compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
