Critical FortiSIEM flaw allows command execution without authentication
On 13 January 2026 a critical vulnerability was identified in FortiSIEM with a CVSSv3 score of 9.4. Tracked as CVE-2025-64155, the flaw allows unauthenticated remote attackers to execute unauthorised code or commands by sending specially crafted TCP requests. An exposed FortiSIEM instance can therefore be fully compromised without valid credentials. Fortinet advises restricting access to the phMonitor port 7900 and upgrading to a patched version.
What this means for your organisation
FortiSIEM is often the logging backbone of the security function, and a compromised SIEM gives an attacker both visibility and the ability to influence the very evidence meant to reveal the intrusion. The flaw requires no authentication, so exposure to the internet or to a broad internal network is itself the risk. This warrants urgent handling rather than the next routine patch window.
Berigo recommends
- Determine whether FortiSIEM is in use, including at your managed service provider.
- Restrict access to port 7900 and upgrade to a patched version in line with Fortinet's advisory.
- Review logs for unexpected activity against the phMonitor service.
- Include security tooling itself in vulnerability management, not only business systems.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch