• News/
  • https://www.theregister.com/2025/11/19/fortinet_confirms_second_fortiweb_0day/

Fortinet 'fesses up to second 0-day within a week

The Register
·
Jessica Lyons
·
Published Nov 19, 2025
·
Updated

Fortinet has confirmed that another flaw in its FortiWeb web application firewall has been exploited as a zero-day and issued a patch, just days after disclosing a critical bug in the same product that attackers had found and abused a month earlier. The new bug, tracked as CVE-2025-58034, is an OS command injection vulnerability that allows authenticated attackers to execute unauthorized code on the underlying system using crafted HTTP requests or CLI commands. Updating FortiWeb devices to the most recent software version fixes the problem. It seems highly likely these two vulnerabilities comprise an exploit chain for unauthenticated RCE "Fortinet has observed this to be exploited in the wild," the vendor said in a Tuesday security advisory that credited Trend Micro researcher Jason McFadyen with finding and reporting the vulnerability. "Trend Micro has observed attacks in the wild using this flaw with around 2,000 detections so far," Trend Micro senior threat researcher Stephen Hilt told The Register. Meanwhile, the US Cybersecurity and Infrastructure Security Agency issued its own alert about the FortiWeb bug on Tuesday, adding it to its Known Exploited Vulnerability catalog and giving federal agencies just seven days to apply the patch. CISA usually sets a 15-day deadline to fix critical patches and a 30-day time limit for implementing high-severity bugs. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the f...

Read full article

Affected Software

1 affected component
Fortinet FortiWeb

Frequently Asked Questions

1

Which FortiWeb vulnerability is confirmed to be exploited, and what does it allow?

CVE-2025-58034 is an OS command injection vulnerability in FortiWeb. Authenticated attackers can use crafted HTTP requests or CLI commands to execute unauthorized code on the underlying system.

2

What action should FortiWeb administrators take?

Update FortiWeb devices to the most recent software version, which fixes the vulnerability.

3

Is exploitation of CVE-2025-58034 confirmed?

Yes. Fortinet said it has observed exploitation in the wild, and Trend Micro reported around 2,000 detections of attacks using the flaw.

4

Could this flaw be used for unauthenticated remote code execution?

The article says it appears highly likely that this vulnerability and the critical FortiWeb bug disclosed days earlier comprise an exploit chain for unauthenticated remote code execution. That chain assessment is presented as likely rather than confirmed.

5

What external response has occurred?

The US Cybersecurity and Infrastructure Security Agency issued an alert and added the FortiWeb vulnerability to its Known Exploited Vulnerability catalog.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203