logo

Fortinet FortiWeb Vulnerability (CVE-2025-64446) Exploited in the Wild for Full Admin Takeover

ID: 29c1de45-07b0-5494-a072-5cd897c1105f

STIX ID: report--29c1de45-07b0-5494-a072-5cd897c1105f

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-16

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Researchers and vendors have documented active exploitation of a critical FortiWeb path-traversal and authentication-bypass vulnerability (CVE-2025-64446) that enables unauthenticated attackers to invoke the fwbcgi handler and create persistent admin accounts; attacks have been observed in the wild since October 2025, the flaw scores CVSSv3.1 9.1, affects many FortiWeb versions (including EOL releases), and has prompted CISA KEV listing and vendor patches and mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.