logo

Critical FortiWeb flaw under attack, allowing complete compromise

ID: df7184da-715c-5e46-a65b-8c1708b919d1

STIX ID: report--df7184da-715c-5e46-a65b-8c1708b919d1

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2025-11-14

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

A critical authentication-bypass flaw in Fortinet FortiWeb is being actively exploited to create administrative accounts and achieve full device takeover; public proof-of-concept code and an exploitation tool have been released, multiple credential payloads were observed, and Fortinet issued a fix in version 8.0.2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.