Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Fortinet Patches CVE-2025-32756 Zero-Day RCE Flaw Exploited in FortiVoice Systems

Fortinet Patches CVE-2025-32756 Zero-Day RCE Flaw Exploited in FortiVoice Systems

Posted on May 14, 2025May 14, 2025 By CWS

Might 14, 2025Ravie LakshmananVulnerability / Community Safety
Fortinet has patched a essential safety flaw that it mentioned has been exploited as a zero-day in assaults concentrating on FortiVoice enterprise cellphone techniques.
The vulnerability, tracked as CVE-2025-32756, carries a CVSS rating of 9.6 out of 10.0.
“A stack-based overflow vulnerability [CWE-121] in FortiVoice, FortiMail, FortiNDR, FortiRecorder, and FortiCamera could permit a distant unauthenticated attacker to execute arbitrary code or instructions by way of crafted HTTP requests,” the corporate mentioned in an advisory.
The corporate mentioned it noticed the flaw being exploited within the wild on FortiVoice techniques, however didn’t disclose the dimensions of the assaults and the id of the risk actors behind them.
It additional famous that the risk actor carried out machine community scans, erased system crash logs, and enabled fcgi debugging to log credentials from the system or SSH login makes an attempt.

The difficulty impacts the next merchandise and variations –

FortiCamera 1.1, 2.0 (Migrate to a set launch)
FortiCamera 2.1.x (Improve to 2.1.4 or above)
FortiMail 7.0.x (Improve to 7.0.9 or above)
FortiMail 7.2.x (Improve to 7.2.8 or above)
FortiMail 7.4.x (Improve to 7.4.5 or above)
FortiMail 7.6.x (Improve to 7.6.3 or above)
FortiNDR 1.1, 1.2, 1.3, 1.4, 1.5, 7.1 (Migrate to a set launch)
FortiNDR 7.0.x (Improve to 7.0.7 or above)
FortiNDR 7.2.x (Improve to 7.2.5 or above)
FortiNDR 7.4.x (Improve to 7.4.8 or above)
FortiNDR 7.6.x (Improve to 7.6.1 or above)
FortiRecorder 6.4.x (Improve to six.4.6 or above)
FortiRecorder 7.0.x (Improve to 7.0.6 or above)
FortiRecorder 7.2.x (Improve to 7.2.4 or above)
FortiVoice 6.4.x (Improve to six.4.11 or above)
FortiVoice 7.0.x (Improve to 7.0.7 or above)
FortiVoice 7.2.x (Improve to 7.2.1 or above)

Fortinet mentioned the vulnerability was found by its product safety crew primarily based on the risk actor exercise that originated from the beneath IP addresses –

198.105.127.124
43.228.217.173
43.228.217.82
156.236.76.90
218.187.69.244
218.187.69.59

Customers of FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera are really useful to use the mandatory fixes to safe their gadgets from lively exploitation makes an attempt. If quick patching shouldn’t be an choice, it is suggested to disable the HTTP/HTTPS administrative interface as a short lived workaround.

Discovered this text fascinating? Comply with us on Twitter  and LinkedIn to learn extra unique content material we put up.

The Hacker News Tags:CVE202532756, Exploited, Flaw, Fortinet, FortiVoice, Patches, RCE, Systems, ZeroDay

Post navigation

Previous Post: Ivanti Patches EPMM Vulnerabilities Exploited for Remote Code Execution in Limited Attacks
Next Post: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Phoenix Contact 

Related Posts

Salesforce Experience Cloud Faces Security Threats Salesforce Experience Cloud Faces Security Threats The Hacker News
Noodlophile Malware Campaign Expands Global Reach with Copyright Phishing Lures Noodlophile Malware Campaign Expands Global Reach with Copyright Phishing Lures The Hacker News
Cloudflare Blocks Record-Breaking 11.5 Tbps DDoS Attack Cloudflare Blocks Record-Breaking 11.5 Tbps DDoS Attack The Hacker News
Hades Attack Targets PyPI: 19 Packages Compromised Hades Attack Targets PyPI: 19 Packages Compromised The Hacker News
Microsoft Mitigates Record 15.72 Tbps DDoS Attack Driven by AISURU Botnet Microsoft Mitigates Record 15.72 Tbps DDoS Attack Driven by AISURU Botnet The Hacker News
Google to Shut Down Dark Web Monitoring Tool in February 2026 Google to Shut Down Dark Web Monitoring Tool in February 2026 The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • JetBrains Fixes Critical Security Flaws in Key Products
  • Dutch Police Break Up €100 Million Fraud Network
  • AI Security Testing Evolves with New Threats
  • Daxin Malware Reappears in Taiwan with New Stupig Backdoor
  • Next.js Enhances Security with Monthly Update Program

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • JetBrains Fixes Critical Security Flaws in Key Products
  • Dutch Police Break Up €100 Million Fraud Network
  • AI Security Testing Evolves with New Threats
  • Daxin Malware Reappears in Taiwan with New Stupig Backdoor
  • Next.js Enhances Security with Monthly Update Program

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark