Stealth-patched FortiWeb vulnerability under active exploitation (CVE-2025-58034)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-58034 | Authenticated OS Command Injection RCE in Fortinet FortiWeb (active exploitation) Fortinet FortiWeb contains an OS command injection flaw (CWE-78) that allows an authenticated attacker to execute unauthorized code on the underlying system by sending crafted HTTP requests or CLI commands. The CVSS vector shows a network-based attack that requires high-privilege (administrative) credentials, so abuse typically follows credential compromise or misuse of a legitimate admin session. Successful exploitation yields high-impact code execution with high confidentiality, integrity, and availability impact on the appliance or virtual machine. Affected deployments span every currently supported FortiWeb branch: 7.0.0-7.0.11, 7.2.0-7.2.11, 7.4.0-7.4.10, 7.6.0-7.6.5, and 8.0.0-8.0.1. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2025-11-18, EPSS assigns a 55.6% 30-day exploitation probability (99th percentile), and media reports describe it as quietly patched by Fortinet before disclosure under active exploitation. Do: Upgrade FortiWeb to a fixed release in your branch per the Fortinet PSIRT advisory (any release beyond the affected ranges above); because the fix was reportedly included quietly in earlier updates, verify your running version before assuming you are safe. Until patched, restrict administrative access (HTTP/HTTPS management interface and CLI) to trusted networks and review admin logs for unexpected logins or commands; U.S. federal agencies must apply mitigations per vendor instructions or follow BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable. | 7.2 | 56% | KEV |
| largetens of thousands of deployed FortiWeb appliances/virtual appliances (public scans typically show thousands-to-tens-of-thousands of FortiWeb instances… | |
| CVE-2025-64446 | Unauthenticated Path Traversal in Fortinet FortiWeb Enables Admin Command Execution CVE-2025-64446 is a relative path traversal vulnerability (CWE-23) in Fortinet's FortiWeb web application firewall that can be triggered by unauthenticated attackers sending crafted HTTP or HTTPS requests to the appliance. Because the flaw occurs in the management plane, an attacker who successfully exploits it gains the ability to execute administrative commands on the device without credentials — effectively an authentication bypass, and news reporting indicates attackers have used it to create rogue admin accounts. Any organization running a FortiWeb release in the affected ranges (7.0.0 through 8.0.1 across the 7.0, 7.2, 7.4, 7.6, and 8.0 branches) is exposed, especially if the management interface is reachable from the internet. The vulnerability is being actively exploited: a public PoC/exploit exists (watchTowr), it carries a critical CVSS 9.8 score, a very high EPSS of 91.8% (100th percentile), and CISA added it to the KEV catalog on 2025-11-14 with a short remediation deadline for federal agencies. Do: Upgrade FortiWeb immediately to a fixed release per Fortinet's advisory — every branch listed in the affected ranges (7.0.x through 8.0.x) has a patched build, so move beyond the listed versions on your branch. Until patched, restrict HTTP/HTTPS access to the FortiWeb management interface to trusted networks/IPs and review the device for unexpected administrator accounts and unfamiliar activity, since reported attacks created rogue admin users. Federal agencies must apply vendor mitigations or discontinue use per BOD 22-01 under the KEV deadline; note the separately tracked FortiWeb CVE-2025-58034 is also being exploited and should be included in the same patch cycle. | 9.8 | 92% | KEV PoC |
| large≈ tens of thousands of internet-exposed FortiWeb appliances (public scan data shows on the order of 10,000–100,000 exposed FortiWeb instances; total… |
Full article297 words · extracted from helpnetsecurity.com · click to collapse
Attackers are actively exploiting another FortiWeb vulnerability (CVE-2025-58034) that Fortinet fixed without making its existence public at the time.
About CVE-2025-58034
CVE-2025-58034 is an OS Command Injection flaw caused by improper neutralization of special elements. It allows authenticated attackers to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.
“Fortinet has observed this to be exploited in the wild,” the company’s Product Security Incident Response Team confirmed in a security advisory published on Tuesday.
CISA also added it to its Known Exploited Vulnerabilities catalog and ordered US federal civilian agencies to address it within a week.
CVE-2025-58034 was privately reported by Trend Micro researcher Jason McFadyen.
It affects FortiWeb versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.5, 7.4.0 through 7.4.10, 7.2.0 through 7.2.11, and 7.0.0 through 7.0.11, and can be remediated by upgrading to FortiWeb 8.0.2, 7.6.6, 7.4.11, 7.2.12, or 7.0.12 (or above), respectively.
These fixed versions were released between October 23 and 31, 2025, with no mention of either CVE-2025-58034 or CVE-2025-64446, an authentication bypass flaw that was recently revealed to had been exploited by attackers for weeks beforehand.
It’s currently unclear whether CVE-2025-58034 was likewise exploited as a zero-day.
What to do?
The Dutch National Cyber Security Center (NCSC-NL) says it expects proof-of-concept (PoC) code or an exploit for CVE-2025-58034 to become publicly available soon and increase the risk of widespread abuse.
Organizations that use FortiWeb but have yet to upgrade to a fixed version should do it sooner rather than later, and check for evidence of compromise.
While CVE-2025-64446 can be temporarily addressed by disabling HTTP or HTTPS for internet facing interfaces, there’s no available workaround for CVE-2025-58034.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/11/19/fortiweb-vulnerability-cve-2025-58034/