It is thought that public exploits for a recently patched remote code execution (RCE) vulnerability identified as CVE-2025-25257 were used to hack several Fortinet FortiWeb instances that were recently infected with web shells.
The Shadowserver Foundation, a threat monitoring platform, reported the exploitation activity after observing 85 infections on July 14 and 77 the next day.
According to the researchers, the CVE-2025-25257 vulnerability is thought to have compromised these Fortinet FortiWeb instances. The pre-authenticated RCE via SQL injection (SQLi) vulnerability CVE-2025-25257 affects FortiWeb versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.4.0 through 7.4.7, and 7.0.0 through 7.0.10.
On July 8, 2025, Fortinet published patches advising users to update to all branches of FortiWeb 7.6.4, 7.4.8, 7.2.11, or 7.0.11.
According to Fortinet, an unauthenticated attacker may be able to execute arbitrary SQL code or instructions via crafted HTTP or HTTPs requests due to a vulnerability in FortiWeb read more about New Fortinet FortiWeb hacks likely linked to public RCE exploits.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
