Fortinet Issues Emergency Patch for Actively Exploited Critical FortiSIEM Bug
ID: 02de1233-5093-58e2-9419-42ccf6a8df0f
STIX ID: report--02de1233-5093-58e2-9419-42ccf6a8df0f
Feed Name: The Cyber Express
Threat Score
Fortinet has disclosed CVE-2025-25256, a critical OS command injection in FortiSIEM (CVSS 9.8) that enables unauthenticated remote code execution and is actively exploited; affected versions span FortiSIEM 6.1–7.3.1 (7.4 not affected). Fortinet urges immediate patching or restricting phMonitor (TCP 7900) access as a mitigation, while reports of widespread brute-force attacks against Fortinet SSL VPNs and a shift toward FortiManager increase urgency.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
