Dozens of Fortinet FortiWeb instances have been compromised with webshells in a widespread hacking campaign, according to the threat monitoring organization The Shadowserver Foundation. The flaw, discovered by security researcher Kentaro Kawane of GMO Cybersecurity, resides in the FortiWeb Fabric Connector, a component that integrates the WAF with other Fortinet security products. The vulnerability at the heart of these attacks, CVE-2025-25257, is a critical pre-authenticated SQL injection (SQLi) flaw in the FortiWeb graphical user interface. Fortinet, a major cybersecurity and firewall vendor, uses the FortiWeb appliance as a Web Application Firewall (WAF) to protect web applications and APIs for large enterprises and government agencies. We are sharing Fortinet FortiWeb instances compromised with webshells likely via CVE-2025-25257. We see 223 FortiWeb management interfaces still exposed on 2025-07-15 (no determination of patch status, but if unpatched for CVE-2025-25257 these are also all likely compromised). The attacks are linked to a critical vulnerability, tracked as CVE-2025-25257, for which public proof-of-concept (PoC) exploits were released just days ago. The Shadowserver Foundation reported on Tuesday that it had identified 77 compromised FortiWeb instances, a slight decrease from 85 the previous day. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. However, on July 11, cybersecurity firm WatchTowr and one of the flaw’s co-discoverers published PoC exploits, dramatically escalating the risk for organizations running unpatched versions. According to Shadowserver, an additional 223 FortiWeb management interfaces remained exposed to the internet as of July 15. The organization noted that active exploitation of the vulnerability has been observed since July 11, the same day researchers made exploit code publicly available. The current wave of attacks confirms cybersecurity experts’ fears that threat actors would quickly weaponize the public exploits.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 16 Jul 2025 16:00:14 +0000