Skip to content

CVE-2025-64155

CVE

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
January 14, 2026
Last Seen
January 15, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability (CVE-2025-64155) in Fortinet's FortiSIEM platform allows unauthenticated remote code execution via crafted TCP requests. This OS command injection flaw affects the phMonitor service, which is crucial for enterprise security monitoring, and is currently being exploited in the...

Fortinet has patched critical vulnerabilities affecting FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager. These security defects, which allow for authentication bypass and could lead to configuration leaks and code execution, were found to be exploitable without authentication. Users with Forti...

Public Exploits

Checking GitHub for proof-of-concept code…