“An improper neutralization of special elements used in an SQL command (‘SQL Injection’) vulnerability [CWE-89] in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests,” Fortinet explained in its advisory. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiWeb vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of the SQL injection flaw in cyberattacks worldwide. Fortinet released security patches on July 8, 2025, and confirmed on July 18 that the vulnerability “has been observed to be exploited in the wild on FortiWeb”. Cybersecurity monitoring organization The Shadowserver Foundation has identified widespread exploitation of the vulnerability, reporting 77 compromised FortiWeb instances as of July 15, 2025. The vulnerability arises from improper neutralization of special elements used in SQL commands, allowing unauthenticated attackers to execute unauthorized SQL code or commands via crafted HTTP or HTTPS requests. CISA strongly urges all organizations to prioritize remediation of this vulnerability, noting that “these types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise”. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The vulnerability resides in FortiWeb’s Fabric Connector component, which serves as a bridge between the firewall and other Fortinet security products. The exploitation campaign began on July 11, 2025, coinciding with the public release of proof-of-concept exploit code by security researchers at watchTowr Labs. Security researchers discovered that attackers can exploit the flaw by sending malicious requests to the /api/fabric/device/status endpoint with crafted Authorization headers. Security experts emphasize the critical importance of rapid patch deployment, especially for internet-facing security appliances that serve as primary defensive barriers against cyber threats.
This Cyber News was published on cybersecuritynews.com. Publication date: Sat, 19 Jul 2025 03:20:09 +0000