logo

FortiWeb Vulnerabilities Exploited: Path Traversal and OS Command Injection

ID: 4e4b5f5d-d593-5dea-8bf1-6312d2bf3e26

STIX ID: report--4e4b5f5d-d593-5dea-8bf1-6312d2bf3e26

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-17

Date Updated: 2026-06-23

...
...

Two critical FortiWeb vulnerabilities are actively being exploited: an unauthenticated relative path traversal (CWE-23) that can execute administrative commands via crafted HTTP/HTTPS requests, and an authenticated OS command injection (CWE-78) that enables execution of unauthorized code via crafted requests or CLI commands; FortiWeb systems are affected (FortiAppSec Cloud is not). Fortinet recommends disabling HTTP/HTTPS on internet-facing interfaces as a temporary mitigation and reviewing configurations and logs for unauthorized changes while upgrades are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.