CVE-2025-25256: Fortinet Rushes to Patch High-Risk FortiSIEM Vulnerability
Red | Vulnerability Report
Download PDFA critical flaw in Fortinet’s FortiSIEM platform, tracked as CVE-2025-25256, is allowing remote attackers to run unauthorized commands without needing to log in. The issue stems from a command injection vulnerability in how the system processes certain CLI requests, putting security operations data and infrastructure at serious risk. With proof-of-concept exploit code already available, organizations are urged to patch immediately, restrict access to management interfaces, and closely monitor for suspicious activity to prevent compromise.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox