logo

CVE-2025-64155: Exploit Code Released for Critical Fortinet FortiSIEM Command Injection Vulnerability

ID: c985ba30-cf48-5a9f-bd14-1753bc2df127

STIX ID: report--c985ba30-cf48-5a9f-bd14-1753bc2df127

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-01-14

Date Updated: 2026-04-22

Author: Scott Caveza

...
...

Tenable reports on CVE-2025-64155, a critical (CVSS 9.4) unauthenticated command injection in Fortinet FortiSIEM for which Horizon3.ai published a proof-of-concept; the advisory lists affected and fixed FortiSIEM versions, recommends patching or limiting access to phMonitor port 7900 as a temporary mitigation, and notes Fortinet devices are historically high-value targets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.