A critical authentication bypass vulnerability in Fortinet FortiWeb web application firewalls has been actively exploited in the wild, allowing unauthenticated attackers to create new administrator accounts and fully compromise affected devices. The flaw, which was silently patched in version 8.0.2, enables attackers to send crafted HTTP POST requests to a specific endpoint (/api/v2.0/cmdb/system/admin%3F/../../../../../cgi-bin/fwbcgi) to add privileged users. Security researchers from watchTowr, Defused, and Rapid7 have confirmed exploitation attempts since early October, with proof-of-concept exploits and detection tools now publicly available. The vulnerability has not yet been assigned a CVE, and Fortinet has not released an official advisory or comment as of the latest reports.
Organizations running FortiWeb versions prior to 8.0.2 are urged to update immediately or restrict public access to the management interface. Security teams should check for unauthorized admin accounts and investigate for potential compromise if their systems have been exposed since early October. The identity of the threat actors remains unknown, but the attacks are widespread and indiscriminate, targeting internet-facing FortiWeb devices. Researchers have published indicators of compromise and recommended urgent mitigation steps to prevent further exploitation.

See which actors are running it and whether you're in range.
10 events from the most recent confirmed update back to the earliest known activity.
By November 17, 2025, reporting stated that CISA had added CVE-2025-64446 to its Known Exploited Vulnerabilities catalog. The listing formally recognized active exploitation and increased pressure on organizations to remediate quickly.
Horizon3.ai released a technical write-up on November 14, 2025 covering the FortiWeb authentication bypass via path traversal tracked as CVE-2025-64446. The publication added further public analysis of exploitation mechanics and affected behavior.
A Metasploit Framework pull request on November 14, 2025 updated the FortiWeb admin-creation module to include CVE-2025-64446 and the Fortinet advisory URL. This reflected rapid weaponization and defender testing support following public disclosure.
On November 14, 2025, reporting said Fortinet confirmed that FortiWeb 8.0.2 had already remediated the vulnerability before the public advisory, despite release notes not explicitly documenting the fix. This drew attention to the vendor's silent patching of an actively exploited flaw.
Fortinet publicly acknowledged the issue on November 14, 2025 in PSIRT advisory FG-IR-25-910, describing it as a path confusion vulnerability in the GUI. The company assigned CVE-2025-64446, provided fixed versions, and recommended mitigations such as restricting HTTP/HTTPS management exposure.
watchTowr Labs published technical analysis on November 14, 2025 showing a FortiWeb exploit chain combining path traversal to reach /cgi-bin/fwbcgi with an impersonation-based authentication bypass. The researchers documented observed exploitation creating new admin accounts and noted their exploit no longer worked on version 8.0.2.
On November 13, 2025, security reporting described active exploitation of a suspected FortiWeb zero-day that had apparently already been fixed in FortiWeb 8.0.2 without public disclosure. Researchers said attackers were using the bug to create new administrative users for persistence.
Rapid7 reported observing an alleged FortiWeb zero-day exploit advertised for sale on a black-hat forum on November 6, 2025. It was unclear whether the offered exploit was the same one later tracked as CVE-2025-64446.
A public proof-of-concept exploit for the FortiWeb issue was published by Defused on October 6, 2025. The disclosure helped surface the vulnerability and demonstrated a path traversal and authentication bypass route to administrator-level access.
Open-source reporting indicates attackers were exploiting the Fortinet FortiWeb vulnerability in targeted attacks starting at least in early October 2025. The activity included unauthenticated access that could be used to create administrative accounts on exposed appliances.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
18 references tracked. Mallory keeps watching after this page renders.
fortiguard.fortinet.com
Open sourceindusface.com
Open sourcecsoonline.com
Open sourcedarkreading.com
Open sourcelabs.watchtowr.com
Open sourcesocradar.io
Open sourcerapid7.com
Open sourcepwndefend.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.