Fortinet confirms silent patch for FortiWeb zero-day exploited in attacks
ID: 1558cd9f-5760-552e-b509-16b53728d04d
STIX ID: report--1558cd9f-5760-552e-b509-16b53728d04d
Feed Name: Bleeping Computer
Fortinet disclosed and silently patched a critical FortiWeb GUI path confusion/path traversal zero-day (CVE-2025-64446) that allows unauthenticated attackers to execute administrative commands and create local admin accounts via crafted HTTP(S) requests; proof-of-concept exploits and attack activity were observed in the wild. Fortinet released FortiWeb 8.0.2 (and patches for 7.6, 7.4, 7.2, 7.0 series) on October 28; CISA added the CVE to its exploited-vulnerabilities catalog and ordered federal agencies to patch by November 21. Mitigations include upgrading to patched versions, disabling internet-facing management interfaces, restricting access to trusted networks, and auditing for unauthorized admin accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
