U.S. CISA adds a new Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 19, 13:48 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2025-58034CVE-2025-6444660
New FortiWeb zero-day CVE-2025Security Affairs·Nov 19, 06:55 UTC · Nov 19, 2025Exploit / PoC in the wildCVE-2025-58034CVE-2025-6444660
Fortinet FortiWeb flaw CVE-2025Security Affairs·Jul 19, 16:25 UTC · Jul 19, 2025Exploit / PoC in the wildCVE-2025-2525760
Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin AccountsThe Hacker News·Nov 17, 14:23 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-6444660
U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Nov 15, 06:58 UTC · Nov 15, 2025Exploit / PoC in the wildCVE-2025-6444660
U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 20, 13:38 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-2525760
Fortinet Issues Patches for 40 Flaws Affecting FortiWeb, FortiOS, FortiNAC, and FortiProxyThe Hacker News·Feb 23, 03:50 UTC · Feb 23, 2023Vulnerability in the wildCVE-2022-39952CVE-2021-4275660
Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited in the WildThe Hacker News·Nov 20, 04:35 UTC · Nov 20, 2025Exploit / PoC in the wildCVE-2025-58034CVE-2025-6444660
Exploits for unauthenticated FortiWeb RCE are public, so patch quickly! (CVE-2025-25257)Help Net Security·Jul 19, 15:00 UTC · Jul 19, 2025Vulnerability in the wildCVE-2025-2525760
A suspected Fortinet FortiWeb zero-day is actively exploited, researchers warnHelp Net Security·Nov 16, 15:28 UTC · Nov 16, 2025Exploit / PoC in the wildCVE-2025-6444660
Critical FortiWeb flaw under attack, allowing complete compromiseSecurity Affairs·Nov 14, 12:41 UTC · Nov 14, 2025Exploit / PoC in the wildCVE-2022-4068460
November 2025 CVE Landscape: 10 Critical Vulnerabilities Show 69% Drop from OctoberRecorded Future·Dec 10, 00:00 UTC · Dec 10, 2025Vulnerability in the wildCVE-2025-64446CVE-2025-58034CVE-2025-21042+1 CVEs60
Patch immediately: CVE-2025-25257 PoC enables remote code execution on Fortinet FortiWebSecurity Affairs·Jul 13, 18:10 UTC · Jul 13, 2025Exploit / PoC in the wildCVE-2025-2525760
Stealth-patched FortiWeb vulnerability under active exploitation (CVE-2025-58034)Help Net Security·Nov 19, 00:00 UTC · Nov 19, 2025Vulnerability in the wildCVE-2025-58034CVE-2025-6444660
U.S. CISA adds a flaw in multiple Fortinet products to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 17, 08:17 UTC · Dec 17, 2025Exploit / PoC in the wildCVE-2025-59718CVE-2025-5971960
Unpatched Remote Hacking Flaw Disclosed in Fortinet's FortiWeb WAFThe Hacker News·Aug 19, 06:50 UTC · Aug 19, 2021Vulnerability in the wildCVE-2021-22123CVE-2020-29015CVE-2018-13379+2 CVEs60
Week in review: Stealth-patched FortiWeb vulnerability under active exploitation, Logitech data breachHelp Net Security·Nov 23, 00:00 UTC · Nov 23, 2025Data breach in the wildCVE-2025-13223CVE-2025-58034CVE-2025-1100160
Week in review: Windows kernel flaw patched, suspected Fortinet FortiWeb zero-day exploitedHelp Net Security·Nov 16, 00:00 UTC · Nov 16, 2025Exploit / PoC in the wildCVE-2025-12480CVE-2025-21042CVE-2025-62215+2 CVEs60
Week in review: Google fixes zero-day vulnerability in Chrome, critical SQL injection flaw in FortiWebHelp Net Security·Jul 20, 00:00 UTC · Jul 20, 2025Exploit / PoC in the wildCVE-2025-6558CVE-2025-2525760
⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & MoreThe Hacker News·Nov 24, 12:32 UTC · Nov 24, 2025Malware in the wildCVE-2025-58034CVE-2025-64446CVE-2025-13223+12 CVEs60
Fortinet’s delayed alert on actively exploited defect put defenders at a disadvantageCyberScoop·Nov 17, 21:01 UTC · Nov 17, 2025Exploit / PoC in the wildCVE-2025-6444660
Fortinet Patches CVE-2026-24858 After Active FortiOS SSO Exploitation DetectedThe Hacker News·Jan 29, 06:05 UTC · Jan 29, 2026Vulnerability in the wildCVE-2026-2485860
CISA gives federal agencies one week to patch exploited Fortinet bugThe Record·Nov 17, 13:33 UTC · Nov 17, 2025Vulnerability in the wildCVE-2025-64446160
⚡ Weekly Recap: Fortinet Exploited, China's AI Hacks, PhaaS Empire Falls & MoreThe Hacker News·Nov 17, 12:37 UTC · Nov 17, 2025Exploit / PoC in the wildCVE-2025-64446CVE-2025-64740CVE-2025-64741+24 CVEs60
Fortinet plugs critical security hole in FortiNAC, with a PoC incoming (CVE-2022-39952)Help Net Security·Feb 20, 00:00 UTC · Feb 20, 2023Exploit / PoC in the wildCVE-2022-39952CVE-2021-42756CVE-2022-4247560
Fortinet FortiNAC CVE-2022-39952 flaw exploited in the wild hours after release of PoC exploitSecurity Affairs·Feb 23, 19:45 UTC · Feb 23, 2023Exploit / PoC in the wildCVE-2022-39952CVE-2021-4275660
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code ExecutionThe Hacker News·Feb 10, 13:59 UTC · Feb 10, 2026Vulnerability in the wildCVE-2026-21643CVE-2026-2485860
Fortinet’s latest zero-day vulnerability carries frustrating familiarities for customersCyberScoop·Jan 29, 04:52 UTC · Jan 29, 2026Exploit / PoC in the wildCVE-2026-24858CVE-2025-5971860
U.S. CISA adds a flaw in multiple Fortinet products to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 28, 19:26 UTC · Jan 28, 2026Exploit / PoC in the wildCVE-2026-2485860
Fortinet patches actively exploited FortiOS SSO auth bypass (CVE-2026Security Affairs·Jan 28, 15:58 UTC · Jan 28, 2026Vulnerability in the wildCVE-2026-24858CVE-2025-59718CVE-2025-5971960
Fortinet starts patching exploited FortiCloud SSO zero-day (CVE-2026-24858)Help Net Security·Jan 28, 00:00 UTC · Jan 28, 2026Exploit / PoC in the wildCVE-2026-24858CVE-2025-5971860
December 2025 CVE Landscape: 22 Critical Vulnerabilities Mark 120% Surge, React2Shell Dominates Threat ActivityRecorded Future·Jan 13, 00:00 UTC · Jan 13, 2026Vulnerability in the wildCVE-2025-55182CVE-2025-20393CVE-2025-8110+1 CVEs60
WatchGuard Warns of Active Exploitation of Critical Fireware OS VPN VulnerabilityThe Hacker News·Dec 23, 04:10 UTC · Dec 23, 2025Vulnerability in the wildCVE-2025-14733CVE-2025-59718CVE-2025-59719+1 CVEs60
U.S. CISA adds a flaw in WatchGuard Fireware OS to its Known Exploited Vulnerabilities catalogSecurity Affairs·Dec 20, 10:26 UTC · Dec 20, 2025Exploit / PoC in the wildCVE-2025-14733CVE-2025-59718CVE-2025-59719+1 CVEs60
Adios 2025, you won’t be missedCisco Talos·Dec 18, 19:00 UTC · Dec 18, 2025Ransomware in the wildCVE-2025-59718CVE-2025-5971960
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication BypassThe Hacker News·Dec 17, 03:57 UTC · Dec 17, 2025Vulnerability in the wildCVE-2025-59718CVE-2025-5971960
Attackers are exploiting auth bypass vulnerability on FortiGate firewalls (CVE-2025-59718)Help Net Security·Dec 17, 00:00 UTC · Dec 17, 2025Vulnerability in the wildCVE-2025-59718CVE-2025-5971960
⚡ Weekly Recap: NFC Fraud, Curly COMrades, NThe Hacker News·Nov 20, 10:46 UTC · Nov 20, 2025Phishing & fraud in the wildCVE-2025-8875CVE-2025-8876CVE-2025-26633+36 CVEs60
Security Affairs newsletter Round 550 by Pierluigi PaganiniSecurity Affairs·Nov 16, 15:27 UTC · Nov 16, 2025Ransomware in the wildCVE-2025-1248060