Fortinet has confirmed that another flaw in its FortiWeb web application firewall has been exploited as a zero-day and issued a patch, just days after disclosing a critical bug in the same product that attackers had found and abused a month earlier. The new bug, tracked as CVE-2025-58034, is an OS command injection vulnerability that allows authenticated attackers to execute unauthorized code on the underlying system using crafted HTTP requests or CLI commands. Updating FortiWeb devices to the most recent software version fixes the problem. It seems highly likely these two vulnerabilities comprise an exploit chain for unauthenticated RCE "Fortinet has observed this to be exploited in the wild," the vendor said in a Tuesday security advisory that credited Trend Micro researcher Jason McFadyen with finding and reporting the vulnerability. "Trend Micro has observed attacks in the wild using this flaw with around 2,000 detections so far," Trend Micro senior threat researcher Stephen Hilt told The Register. Meanwhile, the US Cybersecurity and Infrastructure Security Agency issued its own alert about the FortiWeb bug on Tuesday, adding it to its Known Exploited Vulnerability catalog and giving federal agencies just seven days to apply the patch. CISA usually sets a 15-day deadline to fix critical patches and a 30-day time limit for implementing high-severity bugs. "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the f...
Fortinet 'fesses up to second 0-day within a week
Affected Software
Frequently Asked Questions
Which FortiWeb vulnerability is confirmed to be exploited, and what does it allow?
CVE-2025-58034 is an OS command injection vulnerability in FortiWeb. Authenticated attackers can use crafted HTTP requests or CLI commands to execute unauthorized code on the underlying system.
What action should FortiWeb administrators take?
Update FortiWeb devices to the most recent software version, which fixes the vulnerability.
Is exploitation of CVE-2025-58034 confirmed?
Yes. Fortinet said it has observed exploitation in the wild, and Trend Micro reported around 2,000 detections of attacks using the flaw.
Could this flaw be used for unauthenticated remote code execution?
The article says it appears highly likely that this vulnerability and the critical FortiWeb bug disclosed days earlier comprise an exploit chain for unauthenticated remote code execution. That chain assessment is presented as likely rather than confirmed.
What external response has occurred?
The US Cybersecurity and Infrastructure Security Agency issued an alert and added the FortiWeb vulnerability to its Known Exploited Vulnerability catalog.