ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

A suspected Fortinet FortiWeb zero-day is actively exploited, researchers warn

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-64446

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-64446
Unauthenticated Path Traversal in Fortinet FortiWeb Enables Admin Command Execution

CVE-2025-64446 is a relative path traversal vulnerability (CWE-23) in Fortinet's FortiWeb web application firewall that can be triggered by unauthenticated attackers sending crafted HTTP or HTTPS requests to the appliance. Because the flaw occurs in the management plane, an attacker who successfully exploits it gains the ability to execute administrative commands on the device without credentials — effectively an authentication bypass, and news reporting indicates attackers have used it to create rogue admin accounts. Any organization running a FortiWeb release in the affected ranges (7.0.0 through 8.0.1 across the 7.0, 7.2, 7.4, 7.6, and 8.0 branches) is exposed, especially if the management interface is reachable from the internet. The vulnerability is being actively exploited: a public PoC/exploit exists (watchTowr), it carries a critical CVSS 9.8 score, a very high EPSS of 91.8% (100th percentile), and CISA added it to the KEV catalog on 2025-11-14 with a short remediation deadline for federal agencies.

Do: Upgrade FortiWeb immediately to a fixed release per Fortinet's advisory — every branch listed in the affected ranges (7.0.x through 8.0.x) has a patched build, so move beyond the listed versions on your branch. Until patched, restrict HTTP/HTTPS access to the FortiWeb management interface to trusted networks/IPs and review the device for unexpected administrator accounts and unfamiliar activity, since reported attacks created rogue admin users. Federal agencies must apply vendor mitigations or discontinue use per BOD 22-01 under the KEV deadline; note the separately tracked FortiWeb CVE-2025-58034 is also being exploited and should be included in the same patch cycle.

9.892% KEV PoC
  • Fortinet FortiWeb 7.0.0 through 7.0.11
  • Fortinet FortiWeb 7.2.0 through 7.2.11
  • Fortinet FortiWeb 7.4.0 through 7.4.9
  • +2 more
large≈ tens of thousands of internet-exposed FortiWeb appliances (public scan data shows on the order of 10,000–100,000 exposed FortiWeb instances; total…
Full article436 words · extracted from helpnetsecurity.com · click to collapse

A suspected (but currently unidentified) zero-day vulnerability in Fortinet FortiWeb is being exploited by unauthenticated attackers to create new admin accounts on vulnerable, internet-facing devices.

Fortinet FortiWeb zero-day exploited

Whether intentionally or accidentally, the vulnerability (or this specific path for triggering it) has been addressed in the latest FortiWeb version (8.0.2), Rapid7 researchers confirmed.

Exploitation in the wild

Exploitation attempts were first observed at the beginning of October by threat intelligence company Defused, after one of their honeypots had been targeted.

The now publicly available proof-of-concept exploit has been tested by Rapid7 and watchTowr researchers, and the latter have also published a script that can be used to detect if a specific FortiWeb is vulnerable to this authentication bypass flaw.

Fortinet hasn’t published a security advisory that might identify this vulnerability and has yet to officially comment on the matter.

What to do?

“Exploitation of this new vulnerability allows an attacker with no existing level of access to gain administrator-level access to the FortiWeb Manager panel and websocket command-line interface,” Rapid7 researchers explained.

To prevent exploitation, Fortinet customers using the web application firewall have been advised to either update to version 8.0.2 or remove their FortiWeb management interface from the public internet.

Those who haven’t done this since early October should also check for known indicators of compromise and for new, unknown admin user accounts and, if detected, should conduct a full incident investigation.

UPDATE (November 14, 2025, 02:35 a.m. ET):

Fortinet has released a security advisory detailing this actively exploited relative path traversal vulnerability, and confirmed that it has been silently patched in FortiWeb 8.0.2, 7.6.5, 7.4.10, 7.2.12, and 7.0.12.

The flaw has also received a unique identifier: CVE-2025-64446.

Some of these patched versions, including v8.0.2, were released several weeks after the first report of the vulnerability being under attack, but Fortinet apparently (and disappointingly) chose to keep quiet about it.

The security advisory released today confirms that “Fortinet has observed this to be exploited in the wild,” after many other security teams said the same thing.

CISA has added CVE-2025-64446 to its Known Exploited Vulnerability catalog and has given US civilian federal agencies a week to apply mitigations per vendor instructions.

FortiWeb users that can’t update or can’t do it immediately should disable HTTP or HTTPS for internet facing interfaces (since the flaw can be triggered via specially crafted HTTP or HTTPS requests).

“It is recommended that customers review their configuration for and review logs for unexpected modifications, or the addition of unauthorized administrator accounts,” Fortinet advised.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/11/14/fortinet-fortiweb-zero-day-exploited/