CVE-2025-58034General(fortinet / fortiweb)

MEDIUMCVSS 7.2 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet fortiweb systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-11-25. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiweb

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-18); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
fortiweb

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-18: 1Mentions · 2026-04-21: 1Mentions · 2026-08-28: 1Mentions · 2026-09-27: 1Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-08-28: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-04-21: 1Technical Details · 2026-08-28: 102-1804-2108-2809-27
Signal classification2 categories
General
250.0%
Active Exploitation
250.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-181
General1
2026-04-211
Active Exploitation1
2026-08-281
Active Exploitation1
2026-09-271
General1
Full discourse4 posts
  • Germán Fernández@1ZRR4H
    General

    🚩 Vibe coding + FortiWeb exploitation platform (CVE-2025-64446 ⛓️ CVE-2025-58034) + C2 server (?) + #opendir (now off) 💀🤷🏻‍♂️ https://t.co/SUjGlZfpVZ

    Post summary

    The tweet references two FortiWeb CVEs and mentions an exploitation platform, but it offers no concrete details about PoC code, exploit tools, active attacks, or mitigations.

    113422019723.7K
    36.9K followersView on X
  • Cedric Blandamour@CedricBldmr
    General

    @DailyDarkWeb The forum post says "1-day exploit for Fortinet Fortiweb", apparently on versions 8.0 and 8.1 chaining 2 CVEs. This could be linked to CVE-2025-64446 + CVE-2025-58034 chaining. Why does your text mentions "Fortinet Fortigate SSL VPN" and "7.2.x and 7.4.x" ?

    Post summary

    The text reports a forum post claiming a one‑day exploit for Fortinet FortiWeb versions 8.0 and 8.1 that may chain two recent CVEs, but it lacks explicit PoC, named exploit tools, evidence of active exploitation, patches, or detailed technical vulnerability information.

    10010146
    192 followersView on X
  • @pedri77@pedri77
    Active Exploitation

    Fortinet patched a new FortiWeb zero-day, tracked as CVE-2025-58034, which attackers are actively exploiting. Fortinet patched a new FortiWeb zero-day, tracked as CVE-2025-58034 (CVSS score 6.7), which is being actively... https://f.mtr.cool/jmdt6vtk7a

    Post summary

    Fortinet has patched CVE-2025-58034, a zero‑day affecting FortiWeb with CVSS 6.7, and attackers are actively exploiting the vulnerability in the wild.

    0000073
    2.1K followersView on X
  • Grok@grok
    Active Exploitation

    **Here's the thorough list of major Fortinet RCE vulns (2021-Apr 2026), focused on critical/unauth ones in perimeter products. EIT = exploited in the wild (CISA KEV + vendor reports).** - **2022**: CVE-2022-42475 (FortiOS SSL VPN RCE, EIT by China actors) - **2023**: CVE-2023-27997 (FortiGate VPN heap overflow RCE, EIT); CVE-2023-33308 (FortiOS/FortiProxy buffer overflow RCE) - **2024**: CVE-2024-21762 (FortiOS SSLVPN RCE, EIT); CVE-2024-23113 (FortiOS/FortiProxy RCE, EIT) - **2025**: CVE-2025-25257 (FortiWeb pre-auth SQLi→RCE, EIT); CVE-2025-32756 (multi-product buffer overflow RCE, EIT); CVE-2025-58034 (FortiWeb cmd injection RCE, EIT) - **2026**: CVE-2026-21643 (FortiClient EMS SQLi RCE, EIT); CVE-2026-35616 (FortiClient EMS unauth RCE, EIT); CVE-2026-39808/39813 (FortiSandbox unauth RCE) Patches released for all; frequency in exposed devices drives the risk.

    Post summary

    The passage catalogs multiple Fortinet RCE CVEs, notes that many are actively exploited in the wild, and confirms that patches have been released for all affected products.

    00000152
    8.7M followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiweb---

Explore more