Attacks are currently abusing a major Fortinet FortiSIEM vulnerability that has proof-of-concept exploit code available to the public.
The vulnerability (CVE-2025-64155) is a mix of two problems that permit arbitrary writing with admin rights and privilege escalation to root access, according to security researcher Zach Hanley of penetration testing firm Horizon3.ai.
When Fortinet released security updates to fix the vulnerability on Tuesday, it explained that an unauthenticated attacker could execute unauthorized code or commands via crafted TCP requests due to an improper neutralization of special elements used in an OS command (‘OS Command Injection’) vulnerability [CWE-78] in FortiSIEM.
Horizon3.ai posted proof-of-concept exploit code and a technical article outlining how the phMonitor service’s expose of dozens of command handlers that may be called remotely without authentication is the primary cause of the problem read more about Hackers now exploiting critical Fortinet FortiSIEM flaw in attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
