Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

FortiWeb administrators should check their deployed version and plan an update if it falls within the affected ranges. The Cyber Security Agency of Singapore (CSA) reported on 21 November 2025 that CVE-2025-58034 was reportedly being exploited in the wild. The flaw is an operating-system command injection vulnerability that could let an authenticated attacker execute arbitrary code through crafted HTTP requests or CLI commands.

What is CVE-2025-58034?

CVE-2025-58034 is an OS command injection vulnerability, classified as CWE-78, in Fortinet FortiWeb. According to the CSA alert, successful exploitation could allow an authenticated attacker to execute arbitrary code using crafted HTTP requests or CLI commands. The alert does not describe the vulnerability as unauthenticated.

Is CVE-2025-58034 being exploited?

Yes. The CSA said on 21 November 2025 that exploitation was reportedly occurring in the wild. The alert page was last updated on 23 September 2026, but the exploitation statement is a dated report; it does not provide a current attack rate, victim count, or confirmation of ongoing activity on that later update date.

Which FortiWeb versions are affected?

The CSA lists these affected ranges:

FortiWeb branch Affected versions listed by CSA
8.0 8.0.0 through 8.0.1
7.6 7.6.0 through 7.6.5
7.4 7.4.0 through 7.4.10
7.2 7.2.0 through 7.2.11
7.0 7.0.0 through 7.0.11

These ranges are those stated in the CSA alert. It does not include a table of fixed versions, so do not assume that a particular higher release is the correct target without checking Fortinet’s current CVE-specific advisory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Fortinet FortiWeb-VMC02 1 Year FortiWeb Security Service FC-10-VMC02-137-02-12
  • Manufacturer Part: FC-10-VMC02-137-02-12
  • 1 Year Web Security
  • New/Renewal License for FortiWeb-VMC02
  • The license contract is delivered via e-mail within 1-2 business days
  • Fortinet designed support and subscriptions to be continuous. When a customer does not renew by the expiration date, then a lapse in the service period occurs

How should administrators respond?

  1. Inventory the deployment. Identify each FortiWeb appliance or instance and record its installed branch and version using your organization’s established administration process.
  2. Compare versions with the affected ranges. Any installation within a listed range should be treated as affected for this alert.
  3. Check Fortinet’s current guidance. Consult the CSA advisory and follow its link to Fortinet PSIRT for the current branch-specific fixed release and supported upgrade path. The CSA recommends updating affected versions immediately but does not specify exact target versions.
  4. Upgrade using the supported path. Confirm the target release and any intermediate upgrade requirements in Fortinet’s guidance before applying an update. The available alert does not provide upgrade commands or a branch-by-branch target table.

If you suspect that an affected system was compromised, handle that as an incident as well as a patching task: involve your security team or incident-response provider to assess the system. An update addresses the vulnerable software but does not establish whether earlier exploitation occurred.

What is not established by the alert?

The CSA alert supplies affected-version ranges and a qualitative, dated exploitation report. It does not provide a measured attack count, current indicators of compromise, detailed exploit mechanics, or exact fixed releases. A separate New York State Office of Information Technology Services notice also reports Fortinet’s awareness of exploitation, but its publication date was not established: Multiple Vulnerabilities in Fortinet Products Could Allow for Arbitrary Code Execution.

Quick Recap

Bestseller No. 1
Fortinet FortiWeb-VMC02 1 Year FortiWeb Security Service FC-10-VMC02-137-02-12
Fortinet FortiWeb-VMC02 1 Year FortiWeb Security Service FC-10-VMC02-137-02-12
Manufacturer Part: FC-10-VMC02-137-02-12; 1 Year Web Security; New/Renewal License for FortiWeb-VMC02
$1,561.06
Bestseller No. 2
Fortinet FortiWeb-VMC08 1 Year FortiWeb Security Service FC-10-VMC08-137-02-12
Fortinet FortiWeb-VMC08 1 Year FortiWeb Security Service FC-10-VMC08-137-02-12
Manufacturer Part: FC-10-VMC08-137-02-12; 1 Year Web Security; New/Renewal License for FortiWeb-VMC08
$6,693.46
Bestseller No. 3
Bestseller No. 4
Fortinet FortiWeb-VMC04 1 Year Standard Bundle (24x7 FortiCare Plus AV, FortiWeb Security Service, and IP Reputation) FC-10-VMC04-936-02-12
Fortinet FortiWeb-VMC04 1 Year Standard Bundle (24x7 FortiCare Plus AV, FortiWeb Security Service, and IP Reputation) FC-10-VMC04-936-02-12
Hardware Replacement (NBD), Firmware and General Upgrades, 24X7 Support; Manufacturer Part: FC-10-VMC04-936-02-12
$8,616.74
Best Value
Rackmount.IT Rack Mount Kit for Fortinet FortiGate 40F / FortiWifi 40F / FortiADC 60F / FortiWeb 100F – 1U 19” Rackmount – Front-Facing Ports (RM-FR-T14)
  • Custom Rack Mount for Fortinet Appliances – Specifically designed for FortiGate 40F, FortiWifi 40F, FortiADC 60F, and FortiWeb 100F models to securely mount in standard 19” racks.
  • Front-Facing Connections – Repositions rear-facing ports to the front for cleaner, more accessible cable management in network environments.
  • Easy Installation – Assembles in under 5 minutes with included mounting hardware and power supply fixation to prevent accidental disconnections.
  • Space-Saving 1U Design – Compact 1U form factor saves rack space while maintaining ventilation and accessibility.
  • Perfect Fit and Finish – Engineered by Rackmount.IT to match Fortinet dimensions and airflow, ensuring optimal performance and aesthetics.
Rank #4
Fortinet FortiWeb-VMC04 1 Year Standard Bundle (24x7 FortiCare Plus AV, FortiWeb Security Service, and IP Reputation) FC-10-VMC04-936-02-12
  • Hardware Replacement (NBD), Firmware and General Upgrades, 24X7 Support
  • Manufacturer Part: FC-10-VMC04-936-02-12
  • The license contract is delivered via e-mail within 1-2 business days
  • New/Renewal License for FortiWeb-VMC04
  • Fortinet designed support and subscriptions to be continuous. When a customer does not renew by the expiration date, then a lapse in the service period occurs
Rank #2
Fortinet FortiWeb-VMC08 1 Year FortiWeb Security Service FC-10-VMC08-137-02-12
  • Manufacturer Part: FC-10-VMC08-137-02-12
  • 1 Year Web Security
  • New/Renewal License for FortiWeb-VMC08
  • The license contract is delivered via e-mail within 1-2 business days
  • Fortinet designed support and subscriptions to be continuous. When a customer does not renew by the expiration date, then a lapse in the service period occurs

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi