ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds a new Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-58034CVE-2025-64446

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-58034
Authenticated OS Command Injection RCE in Fortinet FortiWeb (active exploitation)

Fortinet FortiWeb contains an OS command injection flaw (CWE-78) that allows an authenticated attacker to execute unauthorized code on the underlying system by sending crafted HTTP requests or CLI commands. The CVSS vector shows a network-based attack that requires high-privilege (administrative) credentials, so abuse typically follows credential compromise or misuse of a legitimate admin session. Successful exploitation yields high-impact code execution with high confidentiality, integrity, and availability impact on the appliance or virtual machine. Affected deployments span every currently supported FortiWeb branch: 7.0.0-7.0.11, 7.2.0-7.2.11, 7.4.0-7.4.10, 7.6.0-7.6.5, and 8.0.0-8.0.1. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2025-11-18, EPSS assigns a 55.6% 30-day exploitation probability (99th percentile), and media reports describe it as quietly patched by Fortinet before disclosure under active exploitation.

Do: Upgrade FortiWeb to a fixed release in your branch per the Fortinet PSIRT advisory (any release beyond the affected ranges above); because the fix was reportedly included quietly in earlier updates, verify your running version before assuming you are safe. Until patched, restrict administrative access (HTTP/HTTPS management interface and CLI) to trusted networks and review admin logs for unexpected logins or commands; U.S. federal agencies must apply mitigations per vendor instructions or follow BOD 22-01 guidance, or discontinue use of the product if mitigations are unavailable.

7.256% KEV
  • Fortinet FortiWeb 8.0.0 - 8.0.1
  • Fortinet FortiWeb 7.6.0 - 7.6.5
  • Fortinet FortiWeb 7.4.0 - 7.4.10
  • +2 more
largetens of thousands of deployed FortiWeb appliances/virtual appliances (public scans typically show thousands-to-tens-of-thousands of FortiWeb instances…
CVE-2025-64446
Unauthenticated Path Traversal in Fortinet FortiWeb Enables Admin Command Execution

CVE-2025-64446 is a relative path traversal vulnerability (CWE-23) in Fortinet's FortiWeb web application firewall that can be triggered by unauthenticated attackers sending crafted HTTP or HTTPS requests to the appliance. Because the flaw occurs in the management plane, an attacker who successfully exploits it gains the ability to execute administrative commands on the device without credentials — effectively an authentication bypass, and news reporting indicates attackers have used it to create rogue admin accounts. Any organization running a FortiWeb release in the affected ranges (7.0.0 through 8.0.1 across the 7.0, 7.2, 7.4, 7.6, and 8.0 branches) is exposed, especially if the management interface is reachable from the internet. The vulnerability is being actively exploited: a public PoC/exploit exists (watchTowr), it carries a critical CVSS 9.8 score, a very high EPSS of 91.8% (100th percentile), and CISA added it to the KEV catalog on 2025-11-14 with a short remediation deadline for federal agencies.

Do: Upgrade FortiWeb immediately to a fixed release per Fortinet's advisory — every branch listed in the affected ranges (7.0.x through 8.0.x) has a patched build, so move beyond the listed versions on your branch. Until patched, restrict HTTP/HTTPS access to the FortiWeb management interface to trusted networks/IPs and review the device for unexpected administrator accounts and unfamiliar activity, since reported attacks created rogue admin users. Federal agencies must apply vendor mitigations or discontinue use per BOD 22-01 under the KEV deadline; note the separately tracked FortiWeb CVE-2025-58034 is also being exploited and should be included in the same patch cycle.

9.892% KEV PoC
  • Fortinet FortiWeb 7.0.0 through 7.0.11
  • Fortinet FortiWeb 7.2.0 through 7.2.11
  • Fortinet FortiWeb 7.4.0 through 7.4.9
  • +2 more
large≈ tens of thousands of internet-exposed FortiWeb appliances (public scan data shows on the order of 10,000–100,000 exposed FortiWeb instances; total…
Full article476 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 19, 2025

U.S. CISA has added a second Fortinet FortiWeb vulnerability in just a few days to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiWeb flaw, tracked as CVE-2025-58034 (CVSS score of 6.7), to its Known Exploited Vulnerabilities (KEV) catalog.

This week, Fortinet patched a new FortiWeb zero-day, tracked as CVE-2025-58034, which is being actively exploited in attacks in the wild. Trend Micro researcher Jason McFadyen reported the vulnerability.

The flaw is an improper neutralization of special elements used in an OS Command (‘OS Command Injection’) vulnerability. An authenticated attacker can trigger the vulnerability to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

“An Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability [CWE-78] in FortiWeb may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.” reads the advisory. “Fortinet has observed this to be exploited in the wild.”

Below are the affected versions:

VersionAffectedSolution
FortiWeb 8.08.0.0 through 8.0.1Upgrade to 8.0.2 or above
FortiWeb 7.67.6.0 through 7.6.5Upgrade to 7.6.6 or above
FortiWeb 7.47.4.0 through 7.4.10Upgrade to 7.4.11 or above
FortiWeb 7.27.2.0 through 7.2.11Upgrade to 7.2.12 or above
FortiWeb 7.07.0.0 through 7.0.11Upgrade to 7.0.12 or above

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by November 25, 2025.

Recently, Fortinet addressed another FortiWeb zero-day, tracked as CVE-2025-64446 (CVSS score of 9.1), actively exploited in attacks in the wild.

The vulnerability is a relative path traversal issue in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11. An attacker can exploit the flaw to execute administrative commands on the system by sending crafted HTTP or HTTPS requests to vulnerable devices.

“A relative path traversal vulnerability [CWE-23] in FortiWeb may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.” reads the advisory. “Fortinet has observed this to be exploited in the wild”

The cybersecurity vendor recommends disabling HTTP/HTTPS on internet-facing interfaces until upgrading. If management access is internal only, the risk is greatly reduced.

Last week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities (KEV) catalog.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/184832/hacking/u-s-cisa-adds-a-new-fortinet-fortiweb-flaw-to-its-known-exploited-vulnerabilities-catalog.html