Fortinet admits it found another worrying zero-day being exploited in attacks



  • Fortinet patched FortiWeb flaw CVE-2025-58034, enabling OS command injection attacks
  • Vulnerable versions span 7.0.0–7.0.11, 7.2.0–7.2.11, 7.4.0–7.4.10, 7.6.0–7.6.5, 8.0.0–8.0.1
  • Actively exploited in the wild, with ~2,000 attack attempts already detected

Fortinet has issued an urgent patch for a high-severity vulnerability in FortiWeb which is apparently being abused in the wild.

FortiWeb is the company’s dedicated web application firewall (WAF), usually installed in front of a website or API and designed to filter out malicious traffic.


https://cdn.mos.cms.futurecdn.net/oURxQ8dw8TJ2KxmqQDaio6-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img