logo

Exploit code public for critical FortiSIEM command injection flaw

ID: c321b17a-0619-5983-a49d-6c7af43f13b1

STIX ID: report--c321b17a-0619-5983-a49d-6c7af43f13b1

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-01-14

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical unauthenticated command-injection vulnerability (CVE-2025-25256) in Fortinet FortiSIEM's phMonitor service permits remote command execution and privilege escalation to root; Horizon3.ai published technical details and a public exploit affecting FortiSIEM versions 6.7–7.5, Fortinet released patches for supported releases and recommends limiting access to the phMonitor port (7900) as a temporary mitigation, and IOC details are provided to help detect compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.