Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogwidely-deployed-product-advisoryperimeter-device-exposure

Multiple Vulnerabilities in Fortinet Products Enable Arbitrary Code Execution and Information Disclosure

Updated 3mo agoFirst seen Nov 19, 20253 sources

Several Fortinet products, including FortiWeb, FortiClient, FortiExtender, FortiMail, FortiPAM, FortiSandbox, FortiADC, FortiVoice, FortiOS, and FortiProxy, have been found to contain multiple vulnerabilities, some of which could allow for arbitrary code execution. The most severe of these vulnerabilities, such as the FortiWeb RCE flaw (CVE-2025-58034), is under active exploitation and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Additionally, a vulnerability in FortiClient for Windows involving active debug code could allow a local attacker to retrieve saved VPN user passwords, posing a significant risk of information disclosure.

Security advisories urge organizations using affected Fortinet products to review available patches and mitigations immediately. The vulnerabilities impact a wide range of Fortinet's security and networking solutions, increasing the urgency for prompt remediation to prevent potential exploitation and compromise of sensitive assets.

Share:
Multiple Vulnerabilities in Fortinet Products Enable Arbitrary Code Execution and Information Disclosure
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Nov 19, 20257mo ago

CISA KEV alert highlights active exploitation of FortiWeb flaw

Public reporting noted CISA's Known Exploited Vulnerabilities alert for CVE-2025-58034, emphasizing that the FortiWeb command-injection vulnerability was being actively exploited. This marked an escalation from vendor disclosure to broader government-backed warning and prioritization.

Nov 18, 20257mo ago

CVE-2025-58034 reported as exploited in the wild

Fortinet and downstream defenders reported that CVE-2025-58034, a FortiWeb remote code execution flaw involving command injection, had been observed under active exploitation. The disclosure increased urgency for organizations using affected Fortinet products to remediate immediately.

Fortinet discloses multiple product vulnerabilities and releases fixes

Fortinet published advisory FG-IR-25-844 covering multiple vulnerabilities across Fortinet products, including information disclosure through debug features and other severe flaws. The vendor made patches available and advised customers to update affected systems.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.