On November 19, 2025, Fortinet disclosed CVE-2025-58034, a critical OS command injection vulnerability in its FortiWeb Web Application Firewall (WAF) product line. The zero-day flaw is being actively exploited in the wild, allowing authenticated attackers to execute arbitrary commands with the privileges of the web server process. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and issued an emergency directive with an aggressive seven-day patching deadline for federal agencies, highlighting the significant risk it poses. Security researchers have already observed around 2,000 exploitation attempts. There is a high risk that this vulnerability could be chained with other flaws, such as the recent authentication bypass CVE-2025-64446, to enable unauthenticated remote code execution (RCE) attacks against internet-facing devices.
CVE-2025-58034 is an OS command injection vulnerability affecting FortiWeb WAFs. An attacker with valid credentials for the device's management interface can execute arbitrary operating system commands by sending specially crafted HTTP requests or using CLI commands. The root cause lies in insufficient input sanitization within the management interface, allowing command-chaining characters (e.g., ;, |, &&) to be passed to the underlying shell.
Fortinet has confirmed the vulnerability affects its FortiWeb product line. While specific version numbers were not detailed in the initial reports, organizations using any version of FortiWeb should assume they are vulnerable and consult Fortinet's security advisory for patched versions. The flaw impacts all form factors, including hardware appliances, virtual machines, and cloud-based instances.
Both Fortinet and CISA have confirmed that CVE-2025-58034 is being actively exploited in the wild. Security vendor Trend Micro, credited with the discovery, reported approximately 2,000 detections of exploitation attempts. The primary concern is the potential for this vulnerability to be chained with CVE-2025-64446, a recently disclosed authentication bypass in the same product. If chained, an unauthenticated attacker could gain full control over a vulnerable FortiWeb appliance, a highly attractive target for threat actors seeking to compromise network traffic or pivot into protected networks.
A successful exploit of CVE-2025-58034 allows an attacker to gain full control over the FortiWeb appliance. This can lead to several severe consequences:
Security teams should hunt for signs of exploitation attempts targeting FortiWeb appliances. These are not confirmed IOCs but expert-generated indicators for hunting.
url_pattern*/api/v2.0/system/maintenance/firmwarecommand_line_patternuname -a; id; ls -lalog_sourceFortiWeb Event Logsnetwork_traffic_patternOutbound connections from FortiWeb management IP;, |, &&, $(...)).sh, bash, or curl being spawned by the web server process.whoami, id, uname, or network enumeration tools like netstat.M1051 - Update Software mitigation.M1035 - Limit Access to Resource Over Network.M1032 - Multi-factor Authentication.Fortinet patches FortiWeb WAF CVE-2025-58034; Metasploit module released, increasing exploitation risk for 7.x/8.x versions.
Fortinet confirms CVE-2025-58034 (medium severity) chains with CVE-2025-64446 (path traversal) for unauthenticated RCE. Patched versions released.
Applying the vendor-supplied patch is the most effective way to remediate the vulnerability.
Restricting network access to the FortiWeb management interface to only authorized personnel and systems reduces the attack surface.
Enforcing MFA on administrator accounts prevents attackers from using stolen credentials to exploit this authenticated vulnerability.
Properly sandboxing the WAF's processes can limit the impact of a successful command injection attack, preventing it from affecting the entire underlying system.
Fortinet discloses CVE-2025-58034 and confirms active exploitation.
CISA adds CVE-2025-58034 to its KEV catalog and issues an emergency directive.
Deadline for U.S. Federal Civilian Executive Branch agencies to patch the vulnerability.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.