CISA FortiWeb remediation order for FCEB agencies
Public Sector Action
Summary
Hide ▲
Show ▼
CISA ordered U.S. federal civilian agencies to secure FortiWeb within one week after the flaw was exploited in zero-day attacks, sharply raising the urgency for federal remediation. The directive covers CVE-2025-58034, an OS command injection issue that can enable unauthorized code execution through crafted HTTP requests or CLI commands. CISA also added the flaw to its Known Exploited Vulnerabilities Catalog under BOD 22-01, setting a deadline of Tuesday, November 25th.
Related Happenings
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/Mitigation
H score46
First: 15.07.2026 17:07
Last: 15.07.2026 17:07
Sources 1
About this happening:
CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/MitigationAbout this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector Action
H score77
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector ActionAbout this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...
CISA KEV directive for Joomla extension flaws
Public Sector Action
H score36
First: 13.07.2026 18:20
Last: 13.07.2026 18:20
Sources 1
About this happening:
CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA KEV directive for Joomla extension flaws
Public Sector ActionAbout this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector Action
H score35
First: 26.06.2026 22:43
Last: 26.06.2026 22:43
Sources 1
About this happening:
CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector ActionAbout this happening: CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
Timeline
-
19.11.2025 15:44 2 articles · 7mo ago
CISA orders FortiWeb remediation for CVE-2025-58034
Legal Policy Action UpdateCISA ordered U.S. federal civilian agencies to secure Fortinet FortiWeb against CVE-2025-58034 within one week after the flaw was used in zero-day attacks, and added the vulnerability to the Known Exploited Vulnerabilities Catalog under BOD 22-01 with a Tuesday, November 25th deadline. CVE-2025-58034 is an OS command injection issue that can allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands, and CISA also cited CVE-2025-64446 as another FortiWeb flaw under recent and ongoing exploitation.
Show sources
- CISA gives govt agencies 7 days to patch new Fortinet flaw — www.bleepingcomputer.com — 19.11.2025 15:44
- CISA gives govt agencies 7 days to patch new Fortinet flaw — www.bleepingcomputer.com — 19.11.2025 15:44