Critical Fortinet FortiWeb WAF Bug Exploited in the Wild
ID: 8140992d-9b1c-5c5d-b803-66958575ff38
STIX ID: report--8140992d-9b1c-5c5d-b803-66958575ff38
Feed Name: Dark Reading
A critical pre-authentication remote code execution vulnerability (CVE-2025-64446) in Fortinet FortiWeb has been actively exploited in the wild; the flaw is a relative path traversal that allows attackers to bypass authentication and execute privileged API commands. Fortinet published patched versions and mitigation guidance (including disabling HTTP/HTTPS on Internet-facing interfaces), the vulnerability carries a CVSS of 9.1 and has been added to CISA's KEV catalog, and security researchers have raised concerns about apparent silent patching and prior detection by external researchers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
