• News/
  • https://www.bleepingcomputer.com/news/security/hackers-now-exploiting-critical-fortinet-fortisiem-vulnerability-in-attacks/

Hackers now exploiting critical Fortinet FortiSIEM flaw in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 16, 2026
·
Updated

A critical Fortinet FortiSIEM vulnerability with publicly available proof-of-concept exploit code is now being abused in attacks. According to security researcher Zach Hanley at penetration testing company Horizon3.ai, who reported the vulnerability (CVE-2025-64155), it is a combination of two issues that allow arbitrary writes with admin permissions and privilege escalation to root access. "An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSIEM may allow an unauthenticated attacker to execute unauthorized code or commands via crafted TCP requests," Fortinet explained on Tuesday, when it released security updates to patch the flaw. Horizon3.ai has published a technical write-up explaining that the root cause of the issue is the exposure of dozens of command handlers on the phMonitor service, which can be invoked remotely without authentication, and it released proof-of-concept exploit code that allows gaining code execution as root by abusing an argument injection to overwrite the /opt/charting/redishb.sh file. The flaw affects FortiSIEM versions 6.7 to 7.5 and can be patched by upgrading to FortiSIEM 7.4.1 or later, 7.3.5 or later, 7.2.7 or later, or 7.1.9 or later. Customers using FortiSIEM 7.0.0 through 7.0.4 and FortiSIEM 6.7.0 through 6.7.10 are advised to migrate to a fixed release. On Tuesday, Fortinet also shared a temporary workaround for admins who can't immediately apply security updates, r...

Read full article

Affected Software

1 affected component
Fortinet FortiSIEM>=6.7<=7.5, >=7.4.1, >=7.3.5, >=7.2.7, >=7.1.9, <7.0.5, >=6.7.0<6.7.10
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in Fortinet's FortiSIEM that is currently being exploited by hackers.

2

What security implications are discussed?

The article highlights the serious security risks posed by the vulnerability, including potential unauthorized access and control over affected systems.

3

What products or software are affected?

The affected product is Fortinet FortiSIEM, specifically versions 6.7 to 7.5 and various updates in between.

4

Is there any proof-of-concept exploit available for this vulnerability?

Yes, the article mentions that there is publicly available proof-of-concept exploit code for the vulnerability.

5

What actions should users take to protect themselves from this vulnerability?

Users are advised to update their FortiSIEM software to the latest versions to mitigate the risks associated with the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203