New Fortinet FortiWeb hacks likely linked to public RCE exploits
It is thought that public exploits for a recently patched remote code execution (RCE) vulnerability identified as CVE-2025-25257 were used to hack several Fortinet FortiWeb instances that were recently infected with web shells.
The Shadowserver Foundation, a threat monitoring platform, reported the exploitation activity after observing 85 infections on July 14 and 77 the next day.
According to the researchers, the CVE-2025-25257 vulnerability is thought to have compromised these Fortinet FortiWeb instances. The pre-authenticated RCE via SQL injection (SQLi) vulnerability CVE-2025-25257 affects FortiWeb versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.4.0 through 7.4.7, and 7.0.0 through 7.0.10.
On July 8, 2025, Fortinet published patches advising users to update to all branch...

