CVE-2021-22123General(fortinet / fortiweb)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiweb

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-12); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
fortiweb

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-12: 1Mentions · 2026-05-10: 1Mentions · 2026-06-01: 1Mentions · 2026-06-28: 104-1205-1006-0106-28
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-04-121
Disclosure1
2026-05-101
General1
2026-06-011
General1
2026-06-281
General1
Full discourse4 posts
  • Ciberseguridad Hoy@ciberseghoy
    General

    Vulnerabilidad en la página de configuración del servidor SAML en FortiWeb (CVE-2021-22123) https://ciberseguridadhoy.es/vulnerabilidad-en-la-pagina-de-configuracion-del-servidor-saml-en-fortiweb-cve-2021-22123/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The text references CVE-2021-22123 affecting the FortiWeb SAML configuration page but does not provide any POc, exploit details, evidence of active exploitation, or remediation information.

    0001044
    236 followersView on X
  • Ciberseguridad Hoy@ciberseghoy
    General

    Vulnerabilidad en la página de configuración del servidor SAML en FortiWeb (CVE-2021-22123) https://ciberseguridadhoy.es/vulnerabilidad-en-la-pagina-de-configuracion-del-servidor-saml-en-fortiweb-cve-2021-22123/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The provided text merely notes a CVE in a FortiWeb server configuration page and links to an external article, with no further details about exploitation, mitigation, or technical specifics.

    0000022
    238 followersView on X
  • Ciberseguridad Hoy@ciberseghoy
    General

    Vulnerabilidad en la página de configuración del servidor SAML en FortiWeb (CVE-2021-22123) https://ciberseguridadhoy.es/vulnerabilidad-en-la-pagina-de-configuracion-del-servidor-saml-en-fortiweb-cve-2021-22123/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The post announces CVE-2021-22123, a vulnerability in the SAML configuration page of FortiWeb, but provides no exploitation details, patches, or technical specifics.

    0000023
    238 followersView on X
  • Ciberseguridad Hoy@ciberseghoy
    Disclosure

    Vulnerabilidad en la página de configuración del servidor SAML en FortiWeb (CVE-2021-22123) https://ciberseguridadhoy.es/vulnerabilidad-en-la-pagina-de-configuracion-del-servidor-saml-en-fortiweb-cve-2021-22123/?utm_source=ReviveOldPost&utm_medium=social&utm_campaign=ReviveOldPost

    Post summary

    The headline announces a FortiWeb SAML configuration page vulnerability (CVE-2021-22123) but lacks any technical, exploit, or mitigation details.

    0000027
    238 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiweb---

Explore more