Critical FortiSIEM Vulnerability Lets Attackers Run Arbitrary Commands via TCP Packets

Fortinet disclosed a critical OS command injection vulnerability in FortiSIEM on January 13, 2026, warning users of a high-risk flaw that lets unauthenticated attackers execute arbitrary code. Tracked as CVE-2025-64155, the issue stems from improper neutralization of special elements in OS commands (CWE-78) within the phMonitor component on port 7900. Attackers can craft malicious TCP […]

The post Critical FortiSIEM Vulnerability Lets Attackers Run Arbitrary Commands via TCP Packets appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: