logo

Fortinet Issues Emergency Patch for Actively Exploited Critical FortiSIEM Bug

ID: 02de1233-5093-58e2-9419-42ccf6a8df0f

STIX ID: report--02de1233-5093-58e2-9419-42ccf6a8df0f

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2025-08-13

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

Fortinet has disclosed CVE-2025-25256, a critical OS command injection in FortiSIEM (CVSS 9.8) that enables unauthenticated remote code execution and is actively exploited; affected versions span FortiSIEM 6.1–7.3.1 (7.4 not affected). Fortinet urges immediate patching or restricting phMonitor (TCP 7900) access as a mitigation, while reports of widespread brute-force attacks against Fortinet SSL VPNs and a shift toward FortiManager increase urgency.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.