CVE-2025-64155General(fortinet / fortisiem)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet fortisiem systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 through 6.7.10 may allow an attacker to execute unauthorized code or commands via crafted TCP requests.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortisiem

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-04); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
fortisiem

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-02-04: 2Mentions · 2026-02-12: 1Mentions · 2026-02-20: 2Mentions · 2026-05-10: 1PoC Mentioned / Linked · 2026-05-10: 1Active Exploitation · 2026-05-10: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-12: 1Technical Details · 2026-02-20: 202-0402-1202-2005-10
Signal classification4 categories
General
233.3%
Disclosure
233.3%
Patch
116.7%
Exploit
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-042
General2
2026-02-121
Patch1
2026-02-202
Disclosure2
2026-05-101
Exploit1
Full discourse6 posts
  • reverseame@reverseame
    Exploit

    CVE-2025-64155: Three Years of Remotely Rooting the Fortinet FortiSIEM https://horizon3.ai/attack-research/disclosures/cve-2025-64155-three-years-of-remotely-rooting-the-fortinet-fortisiem/

    Post summary

    Researchers announced a PoC that allows remote root on FortiSIEM, indicating that the vulnerability has been actively exploited over the past three years.

    12311128012.7K
    22.4K followersView on X
  • ScanNetSecurity@ScanNetSecurity
    General

    GMOサイバー攻撃 ネットde診断 ASM が「FortiSIEM」に存在する深刻な脆弱性「CVE-2025-64155」の検知に対応 https://scan.netsecurity.ne.jp/article/2026/02/05/54562.html?utm_source=twitter&utm_medium=social&utm_content=tweet

    Post summary

    GMO’s diagnostic ASM announces it will detect the severe FortiSIEM vulnerability CVE-2025-64155, but provides no further technical or exploit details.

    00042963
    21.7K followersView on X
  • transilienceai@transilienceai
    Disclosure

    CVE-2025-64155 is a critical unauthenticated remote code execution (RCE) vulnerability in Fortinet FortiSIEM, with CVSS scores reported as 9.4 or 9.8. This allows attackers to execute arbitrary code with root privileges via OS command injection flaws like argument injection in phMonitor. #CyberSecurity #Vulnerability ⚠️

    Post summary

    The post announces a critical RCE vulnerability (CVE‑2025‑64155) in Fortinet FortiSIEM, detailing its CVSS score, impact, and exploitation method.

    1000063
    311 followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport Fortinet Critical Alert: CVE-2025-64155 RCE & Config Leaks Exposed https://securityonline.info/fortinet-critical-alert-cve-2025-64155-rce-config-leaks-exposed/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    A brief alert announcing a critical RCE vulnerability (CVE-2025-64155) in Fortinet products, but lacking further exploit or remediation details.

    1000080
    1.5K followersView on X
  • Bob Skelley@ChannelSkell
    Patch

    Fortinet released fixes for a critical severity ortiSIEM vulnerability (CVE-2025-64155) that stems from improper neutralization of special elements used in OS commands within the phMonitor service (TCP/7900). Learn more in our latest security bulletin. https://livesocial.seismic.com/tuENOO

    Post summary

    Fortinet has issued a patch for CVE‑2025‑64155, a critical vulnerability in the phMonitor service caused by improper command input sanitization.

    0000041
    680 followersView on X
  • てんちゃんノート@note_tenmen
    General

    GMOサイバー攻撃 ネットde診断 ASM が「FortiSIEM」に存在する深刻な脆弱性「CVE-2025-64155」の検知に対応(ScanNetSecurity) https://news.yahoo.co.jp/articles/9545a8e0c8e10ae4f422b8a34b6ff173eab5c0f1

    Post summary

    The article reports that GMO’s Netde diagnosis ASM has added detection for CVE-2025-64155 in FortiSIEM, but offers no technical, exploit, or patch details.

    00000218
    5 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortisiem---
Appfortinetfortisiem7.4.0--

Explore more