NG Solution Team
Technology

What are the details and next steps for CVE-2025-64446 in Fortinet FortiWeb?

A critical zero-day vulnerability, CVE-2025-64446, has been discovered in Fortinet FortiWeb, a web application firewall. This path-traversal flaw is actively being exploited to create unauthorized administrator accounts on affected systems. Attackers can gain full administrator access without authentication, posing significant security risks. Although Fortinet has yet to officially acknowledge the flaw, exploitation has been ongoing since early October 2025. The vulnerability affects FortiWeb versions 8.0.1 and earlier, with a patch available in version 8.0.2, which blocks exploitation attempts. Global activity has been identified, with automated attacks creating admin accounts using specific names and passwords. Organizations are urged to rely on community intelligence and manage their exposure proactively, as Fortinet has not released a formal advisory yet.

Related posts

Who is the new SVP of Technology at Prosegur?

Jessica Williams

How did Paid secure a $21M seed funding?

James Smith

Has Haven Achieved a $30 Million Valuation in Its Seed Funding Round?

Michael Johnson

Leave a Comment

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy