CVE-2025-58034: Fortinet FortiWeb OS Command Injection Vulnerability
CVE-2025-58034 affects Fortinet FortiWeb and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-18.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
CVE-2025-58034 affects Fortinet FortiWeb and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-18.
CVE-2025-13223 affects Google Chromium V8 and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-19.
CVE-2025-61757 affects Oracle Fusion Middleware and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-21.
CVE-2021-26829 affects OpenPLC ScadaBR and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-11-28.
CVE-2025-48572 affects Android Framework and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-12-02.
CVE-2025-48633 affects Android Framework and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-12-02.
CVE-2021-26828 affects OpenPLC ScadaBR and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-12-03.
CVE-2025-55182 affects Meta React Server Components and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-12-05.
CVE-2025-66644 affects Array Networks ArrayOS AG and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-12-08.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.