Close Menu
  • Home
  • Opinion
  • Region
    • Africa
    • Asia
    • Europe
    • Middle East
    • North America
    • Oceania
    • South America
  • AI & Machine Learning
  • Robotics & Automation
  • Space & Deep Tech
  • Web3 & Digital Economies
  • Climate & Sustainability Tech
  • Biotech & Future Health
  • Mobility & Smart Cities
  • Global Tech Pulse
  • Cybersecurity & Digital Rights
  • Future of Work & Education
  • Trend Radar & Startup Watch
  • Creator Economy & Culture
What's Hot

OnePlus 15R 5G cell teased for world launch: Specs and options to anticipate

November 20, 2025

Up-Shut Take a look at the SnackSync PC, a Customized Gaming Rig That Cooks Pasta and Serves Up Dinner

November 20, 2025

WhatsApp will quickly enable iPhone customers to change between private and work accounts

November 20, 2025
Facebook X (Twitter) Instagram LinkedIn RSS
NextTech NewsNextTech News
Facebook X (Twitter) Instagram LinkedIn RSS
  • Home
  • Africa
  • Asia
  • Europe
  • Middle East
  • North America
  • Oceania
  • South America
  • Opinion
Trending
  • OnePlus 15R 5G cell teased for world launch: Specs and options to anticipate
  • Up-Shut Take a look at the SnackSync PC, a Customized Gaming Rig That Cooks Pasta and Serves Up Dinner
  • WhatsApp will quickly enable iPhone customers to change between private and work accounts
  • An Implementation of a Complete Empirical Framework for Benchmarking Reasoning Methods in Trendy Agentic AI Programs
  • Apple reveals the 45 finalists for 2025 App Retailer Awards
  • Detroit breaks floor on photo voltaic neighbourhoods
  • JD.com Enters Native Providers Fray with “JD Overview” Platform
  • ACM SIGAI Autonomous Brokers Award 2026 open for nominations
Thursday, November 20
NextTech NewsNextTech News
Home - Cybersecurity & Digital Rights - Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited within the Wild
Cybersecurity & Digital Rights

Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited within the Wild

NextTechBy NextTechNovember 19, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Follow Us
Google News Flipboard
Fortinet Warns of New FortiWeb CVE-2025-58034 Vulnerability Exploited within the Wild
Share
Facebook Twitter LinkedIn Pinterest Email


Nov 19, 2025Ravie LakshmananVulnerability / Community Safety

Fortinet has warned of a brand new safety flaw in FortiWeb that it mentioned has been exploited within the wild.

The medium-severity vulnerability, tracked as CVE-2025-58034, carries a CVSS rating of 6.7 out of a most of 10.0.

“An Improper Neutralization of Particular Components utilized in an OS Command (‘OS Command Injection’) vulnerability [CWE-78] in FortiWeb might enable an authenticated attacker to execute unauthorized code on the underlying system through crafted HTTP requests or CLI instructions,” the corporate mentioned in a Tuesday advisory.

In different phrases, profitable assaults require an attacker to first authenticate themselves via another means and chain it with CVE-2025-58034 to execute arbitrary working system instructions.

CIS Build Kits

It has been addressed within the following variations –

  • FortiWeb 8.0.0 via 8.0.1 (Improve to eight.0.2 or above)
  • FortiWeb 7.6.0 via 7.6.5 (Improve to 7.6.6 or above)
  • FortiWeb 7.4.0 via 7.4.10 (Improve to 7.4.11 or above)
  • FortiWeb 7.2.0 via 7.2.11 (Improve to 7.2.12 or above)
  • FortiWeb 7.0.0 via 7.0.11 (Improve to 7.0.12 or above)

The corporate credited Development Micro researcher Jason McFadyen for reporting the flaw underneath its accountable disclosure coverage.

Apparently, the event comes days after Fortinet confirmed that it silently patched one other vital FortiWeb vulnerability (CVE-2025-64446, CVSS rating: 9.1) in model 8.0.2.

“We activated our PSIRT response and remediation efforts as quickly as we discovered of this matter, and people efforts stay ongoing,” a Fortinet spokesperson advised The Hacker Information. “Fortinet diligently balances our dedication to the safety of our prospects and our tradition of accountable transparency.”

It is at present not clear why Fortinet opted to patch the failings with out releasing an advisory. However the transfer has left defenders at a drawback, successfully stopping them from mounting an enough response.

“When common expertise distributors fail to speak new safety points, they’re issuing an invite to attackers whereas selecting to maintain that very same info from defenders,” VulnCheck famous final week.

Elevate your perspective with NextTech Information, the place innovation meets perception.
Uncover the most recent breakthroughs, get unique updates, and join with a worldwide community of future-focused thinkers.
Unlock tomorrow’s developments in the present day: learn extra, subscribe to our e-newsletter, and turn out to be a part of the NextTech neighborhood at NextTech-news.com

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
NextTech
  • Website

Related Posts

Hackers Actively Exploiting 7-Zip Symbolic Hyperlink–Primarily based RCE Vulnerability (CVE-2025-11001)

November 19, 2025

What in case your romantic AI chatbot can’t preserve a secret?

November 18, 2025

Google Points Safety Repair for Actively Exploited Chrome V8 Zero-Day Vulnerability

November 18, 2025
Add A Comment
Leave A Reply Cancel Reply

Economy News

OnePlus 15R 5G cell teased for world launch: Specs and options to anticipate

By NextTechNovember 20, 2025

OnePlus 15 5G cell has already been launched within the flagship market, and persons are…

Up-Shut Take a look at the SnackSync PC, a Customized Gaming Rig That Cooks Pasta and Serves Up Dinner

November 20, 2025

WhatsApp will quickly enable iPhone customers to change between private and work accounts

November 20, 2025
Top Trending

OnePlus 15R 5G cell teased for world launch: Specs and options to anticipate

By NextTechNovember 20, 2025

OnePlus 15 5G cell has already been launched within the flagship market,…

Up-Shut Take a look at the SnackSync PC, a Customized Gaming Rig That Cooks Pasta and Serves Up Dinner

By NextTechNovember 20, 2025

Engineer James Bruton likes to create on a regular basis machines that…

WhatsApp will quickly enable iPhone customers to change between private and work accounts

By NextTechNovember 20, 2025

WhatsApp is reportedly engaged on a multi-account assist characteristic for iOS customers.…

Subscribe to News

Get the latest sports news from NewsSite about world, sports and politics.

NEXTTECH-LOGO
Facebook X (Twitter) Instagram YouTube

AI & Machine Learning

Robotics & Automation

Space & Deep Tech

Web3 & Digital Economies

Climate & Sustainability Tech

Biotech & Future Health

Mobility & Smart Cities

Global Tech Pulse

Cybersecurity & Digital Rights

Future of Work & Education

Creator Economy & Culture

Trend Radar & Startup Watch

News By Region

Africa

Asia

Europe

Middle East

North America

Oceania

South America

2025 © NextTech-News. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms Of Service
  • Advertise With Us
  • Write For Us
  • Submit Article & Press Release

Type above and press Enter to search. Press Esc to cancel.

Subscribe For Latest Updates

Sign up to best of Tech news, informed analysis and opinions on what matters to you.

Invalid email address
 We respect your inbox and never send spam. You can unsubscribe from our newsletter at any time.     
Thanks for subscribing!