Multiple Fortinet FortiWeb instances recently infected with web shells are believed to have been compromised using public exploits for a recently patched remote code execution (RCE) flaw tracked as CVE-2025-25257.| BleepingComputer
Kritische RCE-Schwachstelle CVE-2025-25257 in FortiWeb Fabric Connector – PoCs verfügbar, Patch empfohlen.| Greenbone
Experts urged Fortinet customers to immediately apply patches or disable the affected administrative interface.| Cybersecurity Dive