logo

U.S. CISA adds Fortinet FortiWeb flaw to its Known Exploited Vulnerabilities catalog

ID: e30f87f5-2d6f-5cb3-9709-8b13e4658539

STIX ID: report--e30f87f5-2d6f-5cb3-9709-8b13e4658539

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2025-11-15

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added Fortinet FortiWeb CVE-2025-64446 (CVSS 9.1) to its Known Exploited Vulnerabilities catalog after active exploitation was observed; the flaw is a relative path traversal in multiple FortiWeb versions that permits unauthenticated attackers to execute administrative commands and create admin accounts via crafted HTTP POST requests (notably to /api/v2.0/cmdb/system/admin%3F/../../../../../cgi-bin/fwbcgi). PoCs and an exploitation tool have been published, payloads containing created credentials were observed, Fortinet released fixes (e.g., 8.0.2), and CISA ordered agencies to remediate by November 21, 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.