Attack activity surged against CVE-2025-25257, a critical SQL injection flaw in Fortinet FortiWeb that can enable authentication bypass and remote code execution. The vulnerability is rated CVSS 9.8 and affects multiple FortiWeb release branches, with public disclosure followed quickly by observed exploitation attempts beginning days later. Security monitoring reported that scanning and attack traffic increased notably, indicating rapid weaponization of the flaw after disclosure.
Observed exploitation attempts targeted the FortiWeb endpoint /api/fabric/device/status and injected SQL payloads through the Authorization header's Bearer token field. Attack traffic was seen from multiple countries, led by the United States, followed by France, Japan, Germany, and the Netherlands. Organizations running affected FortiWeb versions have been urged to upgrade immediately to vendor-fixed releases to reduce exposure to unauthenticated compromise.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC reported that attacks exploiting CVE-2025-25257 increased during August 2025. Observed attack traffic was led by sources in the United States, followed by France, Japan, Germany, and the Netherlands.
MBSD-SOC reported first seeing attack activity targeting CVE-2025-25257 shortly after disclosure. The observed exploitation attempts included SQL injection payloads placed in the Authorization header Bearer token field against a FortiWeb API endpoint.
Fortinet publicly disclosed CVE-2025-25257, a critical SQL injection vulnerability in FortiWeb that can enable authentication bypass and remote code execution. The issue affects multiple FortiWeb release branches, and users were advised to update to fixed versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.