Related Threat Clusters
-
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
100 articles · Updated November 15, 2025 -
Fortinet Discovers Zero-Day Exploited in Cyber Attacks
Fortinet has identified a zero-day vulnerability, CVE-2025-58034, being actively exploited in cyber attacks. This flaw affects FortiWeb and is part of a broader trend where Fortinet vulnerabilities are frequently…
2 articles · Updated November 21, 2025 -
Fortinet Discovers New Zero-Day Vulnerability Under Exploitation
Fortinet has identified a new zero-day vulnerability, CVE-2025-58034, that is currently being exploited in attacks. This flaw affects FortiWeb and is part of a broader trend of Fortinet vulnerabilities being targeted in…
2 articles · Updated November 21, 2025 -
CISA Warns of Active Exploitation of Oracle Identity Manager Vulnerability CVE-2025-61757
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, is being actively exploited in the wild. This flaw…
31 articles · Updated November 26, 2025 -
Oracle Identity Manager RCE Vulnerability Exploited in Active Attacks
A critical vulnerability in Oracle Identity Manager, tracked as CVE-2025-61757, allows remote code execution (RCE) without authentication. Discovered by Searchlight Cyber researchers, the flaw has been actively…
19 articles · Updated November 21, 2025 -
Over 10,000 Fortinet Firewalls Vulnerable to 2FA Bypass Exploits
More than 10,000 Fortinet firewalls remain exposed to a critical two-factor authentication bypass vulnerability (CVE-2020-12812) that has been actively exploited. This flaw, first disclosed in July 2020, continues to…
6 articles · Updated January 5, 2026 -
Fortinet Addresses Critical SSO Authentication Bypass Vulnerabilities
Fortinet has released security updates for critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO authentication. The vulnerabilities,…
3 articles · Updated December 10, 2025 -
Fortinet Products Vulnerable to Arbitrary Code Execution
Multiple vulnerabilities have been identified in Fortinet products, with the most critical allowing for arbitrary code execution. Exploitation of these vulnerabilities could enable attackers to execute commands in the…
2 articles · Updated January 13, 2026 -
Critical Vulnerabilities in Fortinet FortiWeb Actively Exploited
Fortinet's FortiWeb web application firewall has been compromised by two critical vulnerabilities, CVE-2025-64446 and CVE-2025-58034, both of which are under active exploitation. The first vulnerability allows…
74 articles · Updated November 28, 2025 -
Over 25,000 Fortinet Devices Vulnerable to Attacks via FortiCloud SSO
More than 25,000 Fortinet devices with FortiCloud SSO enabled are exposed to remote attacks due to a critical authentication bypass vulnerability tracked as CVE-2025-59718. The U.S. has the highest number of affected…
2 articles · Updated December 22, 2025
Recent Intelligence Reports
- Over 10K Fortinet firewalls exposed to actively exploited 2FA bypass — Bleepingcomputer · January 2, 2026
- Over 25,000 FortiCloud SSO devices exposed to remote attacks — Bleepingcomputer · December 19, 2025
- Fortinet warns of critical FortiCloud SSO login auth bypass flaws — Bleepingcomputer · December 9, 2025
- Oracle's Identity Fortress Crumbles: CISA Sounds Alarm on Zero — Webpronews · November 24, 2025
- 24th November — Research.Checkpoint · November 24, 2025
- Active Exploitation of Vulnerability in FortiWeb — Csa.Sg · November 21, 2025
- Fortinet admits it found another worrying zero-day being exploited in attacks — Msn · November 21, 2025
- Many Fortinet Security Updates, Renewed Attacks on FortiWeb — Heise.De · November 20, 2025