A critical Fortinet FortiSIEM vulnerability with publicly available proof-of-concept exploit code is now being abused in attacks. According to security researcher Zach Hanley at penetration testing company Horizon3.ai, who reported the vulnerability (CVE-2025-64155), it is a combination of two issues that allow arbitrary writes with admin permissions and privilege escalation to root access. "An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSIEM may allow an unauthenticated attacker to execute unauthorized code or commands via crafted TCP requests," Fortinet explained on Tuesday, when it released security updates to patch the flaw. Horizon3.ai has published a technical write-up explaining that the root cause of the issue is the exposure of dozens of command handlers on the phMonitor service, which can be invoked remotely without authentication, and it released proof-of-concept exploit code that allows gaining code execution as root by abusing an argument injection to overwrite the /opt/charting/redishb.sh file. The flaw affects FortiSIEM versions 6.7 to 7.5 and can be patched by upgrading to FortiSIEM 7.4.1 or later, 7.3.5 or later, 7.2.7 or later, or 7.1.9 or later. Customers using FortiSIEM 7.0.0 through 7.0.4 and FortiSIEM 6.7.0 through 6.7.10 are advised to migrate to a fixed release. On Tuesday, Fortinet also shared a temporary workaround for admins who can't immediately apply security updates, r...
Hackers now exploiting critical Fortinet FortiSIEM flaw in attacks
BleepingComputer
·Sergiu Gatlan
·Published Jan 16, 2026
·Updated
Affected Software
1 affected component
Fortinet FortiSIEM>=6.7<=7.5, >=7.4.1, >=7.3.5, >=7.2.7, >=7.1.9, <7.0.5, >=6.7.0<6.7.10
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in Fortinet's FortiSIEM that is currently being exploited by hackers.
2
What security implications are discussed?
The article highlights the serious security risks posed by the vulnerability, including potential unauthorized access and control over affected systems.
3
What products or software are affected?
The affected product is Fortinet FortiSIEM, specifically versions 6.7 to 7.5 and various updates in between.
4
Is there any proof-of-concept exploit available for this vulnerability?
Yes, the article mentions that there is publicly available proof-of-concept exploit code for the vulnerability.
5
What actions should users take to protect themselves from this vulnerability?
Users are advised to update their FortiSIEM software to the latest versions to mitigate the risks associated with the vulnerability.