CISA gives federal agencies one week to patch exploited Fortinet bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-64446 | Unauthenticated Path Traversal in Fortinet FortiWeb Enables Admin Command Execution CVE-2025-64446 is a relative path traversal vulnerability (CWE-23) in Fortinet's FortiWeb web application firewall that can be triggered by unauthenticated attackers sending crafted HTTP or HTTPS requests to the appliance. Because the flaw occurs in the management plane, an attacker who successfully exploits it gains the ability to execute administrative commands on the device without credentials — effectively an authentication bypass, and news reporting indicates attackers have used it to create rogue admin accounts. Any organization running a FortiWeb release in the affected ranges (7.0.0 through 8.0.1 across the 7.0, 7.2, 7.4, 7.6, and 8.0 branches) is exposed, especially if the management interface is reachable from the internet. The vulnerability is being actively exploited: a public PoC/exploit exists (watchTowr), it carries a critical CVSS 9.8 score, a very high EPSS of 91.8% (100th percentile), and CISA added it to the KEV catalog on 2025-11-14 with a short remediation deadline for federal agencies. Do: Upgrade FortiWeb immediately to a fixed release per Fortinet's advisory — every branch listed in the affected ranges (7.0.x through 8.0.x) has a patched build, so move beyond the listed versions on your branch. Until patched, restrict HTTP/HTTPS access to the FortiWeb management interface to trusted networks/IPs and review the device for unexpected administrator accounts and unfamiliar activity, since reported attacks created rogue admin users. Federal agencies must apply vendor mitigations or discontinue use per BOD 22-01 under the KEV deadline; note the separately tracked FortiWeb CVE-2025-58034 is also being exploited and should be included in the same patch cycle. | 9.8 | 92% | KEV PoC |
| large≈ tens of thousands of internet-exposed FortiWeb appliances (public scan data shows on the order of 10,000–100,000 exposed FortiWeb instances; total… |
Full article590 words · extracted from therecord.media · click to collapse
The federal government confirmed on Friday that hackers are exploiting a vulnerability affecting Fortinet devices that has caused alarm among cybersecurity experts since early October. The Cybersecurity and Infrastructure Security Agency (CISA) gave all federal civilian agencies seven days to patch CVE-2025-64446 and released an advisory that said it is “aware of exploitation.” CISA typically gives agencies 21 days to patch most vulnerabilities added to its list of exploited bugs. CISA warned that if users cannot immediately upgrade affected systems, they should disable HTTP or HTTPS for internet-facing interfaces. Fortinet published an advisory on Friday as well, rating CVE-2025-64446 a “critical” vulnerability and giving it a severity score of 9.1 out of 10. The bug affects Fortinet FortiWeb, a web application firewall used widely across governments and large businesses to detect and block malicious traffic to web applications. Fortinet urged customers to upgrade to patched versions. The issue was first highlighted by cybersecurity firm Defused on October 6. Cybersecurity company watchTowr published a detailed breakdown of the vulnerability and noted that newer versions of the software are not vulnerable to the bug. The company said it is unclear if Fortinet accidentally patched the bug in newer versions of its software or quietly patched it without telling the public. Fortinet declined to answer questions about the timing of the patch, telling Recorded Future News that it activated its response and remediation efforts “as soon as they learned of this matter.” “Fortinet diligently balances our commitment to the security of our customers and our culture of responsible transparency,” a spokesperson said. “With that goal and principle top of mind, we are communicating directly with affected customers to advise on any necessary recommended actions.” Benjamin Harris, watchTowr CEO, said the company is seeing active, indiscriminate in-the-wild exploitation of the vulnerability. The company released a Detection Artefact Generator to enable defenders to identify vulnerable hosts. “Patched in version 8.0.2, the vulnerability allows attackers to perform actions as a privileged user – with in-the-wild exploitation focusing on adding a new administrator account as a basic persistence mechanism for the attackers,” Harris told Recorded Future News. Experts at Rapid7 said they observed that an alleged zero-day exploit targeting FortiWeb was published for sale on a popular cybercriminal forum on November 6. Rapid7 explained that successful exploitation “allows an attacker with no existing level of access to gain administrator-level access to the FortiWeb Manager panel.” Scott Caveza, senior staff research engineer at Tenable, noted that Fortinet devices are frequent targets for hackers and added that this is the 21st vulnerability affecting the company’s products that has been added to CISA’s Known Exploited Vulnerabilities list. “Over the last 24 hours, we’ve seen multiple reports confirming the existence of a new and previously unidentified vulnerability, including several sources reporting that active exploitation has already occurred,” Caveza told Recorded Future News, noting that they have “already seen hundreds of devices, many in the U.S., publicly available on Shodan.” “While it’s unclear why Fortinet is only now releasing its advisory, it serves as a reminder that defenders must remain vigilant and regularly apply updates for critical devices regardless of a vulnerability’s exploitation status. You’re a sitting duck if you don't address these issues in a timely manner.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/fortinet-fortiweb-vulnerability-cisa-advisory