Fortinet FortiWeb has been exploited! Patch Now!

 The US Cybersecurity and Infrastructure Securityn Agency (CISA) has provided an alert on exploitation of Fortinet FortiWeb through a SQL injection vulnerability that is tracked as CVE-2025-25257. The critical vulnerability exists in the following versions of the security product: 7.6.0 through 7.6.3, 7.4.0 through 7.4.7 and 7.2.0 through 7.2.10 and those below 7.0.10. The upgrades for each of the ranges has been provided by Fortinet. For working around the SQL injection vulnerability, the HTTP/HTTPS administrative interface msut be disabled.

Comments

Popular posts from this blog

Four new (from past years) vulnerabilities to be monitored after CISA flags them as exploited

Microsoft warns of SharePoint exploitation, says enable AMSI to stay secure!

Citrix NetScaler ADC and Gateway has been exploited: Patch now!