logo

Critical Fortinet FortiWeb WAF Bug Exploited in the Wild

ID: 8140992d-9b1c-5c5d-b803-66958575ff38

STIX ID: report--8140992d-9b1c-5c5d-b803-66958575ff38

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-11-17

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

A critical pre-authentication remote code execution vulnerability (CVE-2025-64446) in Fortinet FortiWeb has been actively exploited in the wild; the flaw is a relative path traversal that allows attackers to bypass authentication and execute privileged API commands. Fortinet published patched versions and mitigation guidance (including disabling HTTP/HTTPS on Internet-facing interfaces), the vulnerability carries a CVSS of 9.1 and has been added to CISA's KEV catalog, and security researchers have raised concerns about apparent silent patching and prior detection by external researchers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.