Fortinet FortiWeb has been hit by multiple serious vulnerabilities, including CVE-2025-58034, an authenticated OS command injection flaw, and CVE-2025-25257, a pre-authentication SQL injection issue in the Fabric Connector component that can lead to remote code execution. Reporting indicated the command injection bug was under active exploitation, while public advisories described the weakness as enabling attackers to execute operating system commands on affected appliances. The SQL injection flaw affects FortiWeb Fabric Connector versions across the 7.0 to 7.6.x range and is notable because exploitation does not require prior authentication.
Public exploit and detection material quickly emerged for CVE-2025-25257, with GitHub repositories publishing proof-of-concept code and exploitation demonstrations, alongside production-focused detection engineering content to help defenders identify abuse. The combination of active exploitation reporting, internet-facing exposure tracking, and readily available offensive tooling raises the risk for organizations using FortiWeb, particularly where management interfaces or vulnerable connector functionality are exposed.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
A public advisory was issued for CVE-2025-58034, describing an authenticated OS command injection vulnerability in Fortinet FortiWeb. Subsequent references tied the advisory to exploitation concerns around the product.
Cybersecurity Dive reported that a critical Fortinet FortiWeb vulnerability was being actively exploited in the wild. The article indicates exploitation activity had been observed by the time of publication.
Another GitHub repository for CVE-2025-25257 was released, further publicizing exploitation details for the FortiWeb flaw. The project described the issue as a secure pre-authenticated SQL injection affecting FortiWeb.
A GitHub repository providing production-ready detection engineering content for CVE-2025-25257 was published. It focused on helping defenders identify exploitation of the FortiWeb Fabric Connector SQL injection vulnerability.
A public GitHub repository for CVE-2025-25257 was published, demonstrating exploitation of a Fortinet FortiWeb vulnerability. The flaw was described as a pre-authentication SQL injection issue that could lead to remote code execution.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecensys.com
Open sourcecybersecuritydive.com
Open sourcecybersecuritydive.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.