logo

Fortinet confirms silent patch for FortiWeb zero-day exploited in attacks

ID: 1558cd9f-5760-552e-b509-16b53728d04d

STIX ID: report--1558cd9f-5760-552e-b509-16b53728d04d

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2025-11-14

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Fortinet disclosed and silently patched a critical FortiWeb GUI path confusion/path traversal zero-day (CVE-2025-64446) that allows unauthenticated attackers to execute administrative commands and create local admin accounts via crafted HTTP(S) requests; proof-of-concept exploits and attack activity were observed in the wild. Fortinet released FortiWeb 8.0.2 (and patches for 7.6, 7.4, 7.2, 7.0 series) on October 28; CISA added the CVE to its exploited-vulnerabilities catalog and ordered federal agencies to patch by November 21. Mitigations include upgrading to patched versions, disabling internet-facing management interfaces, restricting access to trusted networks, and auditing for unauthorized admin accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.