Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks

A critical vulnerability identified as CVE-2025-64155 has been detected in Fortinet FortiSIEM systems. This vulnerability is currently under active exploitation and poses significant risks due to its ability to allow unauthenticated remote code execution…

A critical vulnerability identified as CVE-2025-64155 has been detected in Fortinet FortiSIEM systems. This vulnerability is currently under active exploitation and poses significant risks due to its ability to allow unauthenticated remote code execution through OS command injection.

The flaw is located in the FortiSIEM phMonitor service, which is responsible for internal data exchange across Super and Worker nodes. Attackers can exploit this vulnerability by sending specially crafted TCP requests to port 7900. These requests target storage configuration endpoints with an elastic type set, injecting arguments into a curl command via XML payloads. This results in arbitrary file writes with administrative privileges, and a chained privilege escalation can provide root access by overwriting executed binaries.

Proof-of-concept code is publicly available on GitHub , showcasing complete remote code execution chains. Fortinet has confirmed that Cloud and Collector nodes are not affected by this vulnerability.

Product Version Affected Range Fixed Version

FortiSIEM 6.7 6.7.0 through 6.7.10 Migrate to a fixed release

FortiSIEM 7.0 7.0.0 through 7.0.4 Migrate to a fixed release

FortiSIEM 7.1 7.1.0 through 7.1.8 7.1.9 or above

FortiSIEM 7.2 7.2.0 through 7.2.6 7.2.7 or above

FortiSIEM 7.3 7.3.0 through 7.3.4 7.3.5 or above

A critical vulnerability identified as CVE-2025-64155 has been detected in Fortinet FortiSIEM systems.
Henry Dalton · Thehackingpost

FortiSIEM 7.4 7.4.0 7.4.1 or above

FortiSIEM 7.5 Not affected N/A

FortiSIEM Cloud Not affected N/A

Exploitation attempts have been logged as PHL_ERROR entries in /opt/phoenix/log/phoenix.log, revealing attacker URLs and file paths. The unauthenticated nature of the flaw, along with the exposure of SIEM systems, increases the risk of log tampering, data exfiltration, or lateral movement.

Indicators of compromise include recent IP addresses involved in attacks:

IP Address ASN/Organization

Advertisement

167.17.179[.]109 Baxet Group Inc.

103.224.84[.]76 Siamdata Communication

209.126.11[.]25 Contabo

120.231.127[.]227 China Mobile Communications Group

129.226.190[.]169 Tencent

220.181.41[.]80 IDC, China Telecommunications Corporation

Organizations using FortiSIEM should upgrade Super/Worker nodes immediately according to Fortinet’s advisory . As a temporary measure, block external access to TCP port 7900. Monitoring phMonitor logs for irregularities and using endpoint detection and response (EDR) tools to scan for indicators of compromise (IOCs) is also advised.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories