FortiWeb Systems Compromised via Webshells After Public PoC Release
Score: 77/100
5 articles
100.0% coherence
2 days ago
Activity Timeline
A Vulnerability in FortiWeb Could Allow for SQL In...
CIS Security Advisories
Jul 08
19:17
Exploits for pre-auth Fortinet FortiWeb RCE flaw r...
BleepingComputer
Jul 11
19:41
New Fortinet FortiWeb hacks likely linked to publi...
BleepingComputer
Jul 16
14:58
Fortinet FortiWeb Instances Hacked With Webshells ...
Cybersecurity News
Jul 16
15:57
FortiWeb Systems Compromised via Webshells After P...
GB Hackers
Primary Article
Jul 17
05:21
Primary Article
GB Hackers 6 hours ago
FortiWeb Systems Compromised via Webshells After Public PoC Release
A widespread cyberattack campaign has successfully compromised dozens of Fortinet FortiWeb instances throughwebshelldeployment, exploiting a critical vulnerability for which proof-of-concept code became publicly available just days ago.
The rapid weaponization of the exploit demonstrates the immediate risks organizations face when security flaws become public knowledge.
Critical Vulnerability Details and Impact
The attacks center aroundCVE-2025-25257, a critical pre-authenticated SQL injection vulnerability affecting Fortinet’s FortiWeb Web Application Firewall systems.
This flaw, with a severe CVSS score of 9.6 out of 10, allows unauthenticated attackers to execute unauthorized code remotely by sending specially crafted HTTP requests to vulnerable systems.
The vulnerability resides specifically in the FortiWeb Fabric Connector component, which integrates the WAF with other Fortinet security products.
Security research...
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Unlock Cluster AI
Join ThreatCluster Intelligence to access AI-generated executive, technical, and remediation briefs.
New Fortinet FortiWeb hacks likely linked to public RCE exploits
Bill Toulas
July 16, 2025
10:58 AM
0
Multiple Fortinet FortiWeb instances recently infected with web shells are believed to have been c...
Exploits for pre-auth Fortinet FortiWeb RCE flaw released, patch now
Lawrence Abrams
July 11, 2025
03:41 PM
0
Proof-of-concept exploits have been released for a critical SQLi vulnerability in Fortinet...
A Vulnerability in FortiWeb Could Allow for SQL Injection
MS-ISAC ADVISORY NUMBER:
DATE(S) ISSUED:
OVERVIEW:
A vulnerability has been discovered FortiWeb, which could allow for SQL injection.FortiWeb ...
Dozens of Fortinet FortiWeb instances have been compromised with webshells in a widespread hacking campaign, according to the threat monitoring organization The Shadowserver Foundation.
The attacks ar...
Save to Folder
Choose a folder to save this cluster:
We use cookies
We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.
Cookie Settings
Essential Cookies
Required for the website to function. Cannot be disabled.
Session management and authentication
Security and fraud prevention
Cookie consent preferences
Analytics Cookies
Help us understand how visitors interact with our website.