Multiple Vulnerabilities in Fortinet Products Enable Arbitrary Code Execution and Information Disclosure
Several Fortinet products, including FortiWeb, FortiClient, FortiExtender, FortiMail, FortiPAM, FortiSandbox, FortiADC, FortiVoice, FortiOS, and FortiProxy, have been found to contain multiple vulnerabilities, some of which could allow for arbitrary code execution. The most severe of these vulnerabilities, such as the FortiWeb RCE flaw (CVE-2025-58034), is under active exploitation and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. Additionally, a vulnerability in FortiClient for Windows involving active debug code could allow a local attacker to retrieve saved VPN user passwords, posing a significant risk of information disclosure.
Security advisories urge organizations using affected Fortinet products to review available patches and mitigations immediately. The vulnerabilities impact a wide range of Fortinet's security and networking solutions, increasing the urgency for prompt remediation to prevent potential exploitation and compromise of sensitive assets.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
3 events from the most recent confirmed update back to the earliest known activity.
CISA KEV alert highlights active exploitation of FortiWeb flaw
Public reporting noted CISA's Known Exploited Vulnerabilities alert for CVE-2025-58034, emphasizing that the FortiWeb command-injection vulnerability was being actively exploited. This marked an escalation from vendor disclosure to broader government-backed warning and prioritization.
CVE-2025-58034 reported as exploited in the wild
Fortinet and downstream defenders reported that CVE-2025-58034, a FortiWeb remote code execution flaw involving command injection, had been observed under active exploitation. The disclosure increased urgency for organizations using affected Fortinet products to remediate immediately.
Fortinet discloses multiple product vulnerabilities and releases fixes
Fortinet published advisory FG-IR-25-844 covering multiple vulnerabilities across Fortinet products, including information disclosure through debug features and other severe flaws. The vendor made patches available and advised customers to update affected systems.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
CISA KEV Alert: FortiWeb RCE Flaw (CVE-2025-58034) Under Active Exploitation for Command Injection
securityonline.info
Open sourceInformation disclosure through debug features
fortiguard.fortinet.com
Open sourceMultiple Vulnerabilities in Fortinet Products Could Allow for Arbitrary Code Execution
cisecurity.org
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


