logo

Fortinet FortiWeb flaw with public PoC exploited to create admin users

ID: b5f4887b-47ab-5a91-88dc-fe71b0e4c2c1

STIX ID: report--b5f4887b-47ab-5a91-88dc-fe71b0e4c2c1

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-11-14

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

A Fortinet FortiWeb path traversal flaw (affecting versions up to 8.0.1) is being actively exploited to create administrative users without authentication; researchers observed global scanning and exploitation, reported specific usernames/passwords and source IPs, and confirmed successful account creation. Administrators are advised to upgrade to FortiWeb 8.0.2, audit logs for fwbcgi requests and unusual admin accounts, and restrict management interfaces to trusted networks or VPN-only access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.