A critical zero-day vulnerability in Fortinet's FortiWeb Web Application Firewall (WAF), tracked as CVE-2025-64446, has been actively exploited by threat actors since early October 2025. The flaw, which combines a path traversal and authentication bypass, allows attackers to create malicious administrative accounts and execute privileged actions on vulnerable FortiWeb devices. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply patches by November 21, 2025. The vulnerability affects multiple FortiWeb versions, including 8.0.0 through 8.0.1, 7.6.0 through 7.6.4, 7.4.0 through 7.4.9, 7.2.0 through 7.2.11, and 7.0.0 through 7.0.11, and is being exploited in the wild to gain unauthorized administrative access.
Security briefings and technical reports confirm that attackers are leveraging crafted HTTP or HTTPS requests to exploit the flaw, enabling them to bypass authentication and perform administrative actions. The exploitation campaign has prompted urgent patching advisories and highlights the ongoing risk posed by unpatched WAF appliances in enterprise environments. While the identity of the threat actors remains unknown, the rapid weaponization of this vulnerability underscores the importance of timely patch management and monitoring for suspicious administrative account creation on FortiWeb devices.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Researchers identified a malicious Visual Studio Code extension named 'susvsex' in the official marketplace. The extension was reported to include ransomware and data-stealing functionality.
A critical CVSS 9.8 vulnerability was disclosed in the widely used expr-eval JavaScript library. The package is commonly used in online calculators and natural-language-processing tools, increasing potential downstream exposure.
DANABOT was reported to have undergone a substantial code rewrite that improved its speed and stability. The update was described as occurring after earlier law-enforcement pressure from Operation Endgame.
Microsoft issued its November Patch Tuesday security updates, addressing 68 vulnerabilities, including one zero-day. The release was highlighted as a major defensive response to active and emerging threats.
A zero-day vulnerability in Fortinet FortiWeb, tracked as CVE-2025-64446, was disclosed as allowing attackers to create administrator accounts through crafted HTTP or HTTPS requests. Multiple FortiWeb versions were reported as affected.
Europol coordinated a new phase of Operation Endgame targeting major cybercrime services and malware families, including RHADAMANTHYS, VENOMRAT, and the ELYSIUM botnet. The action represented a fresh law-enforcement escalation against criminal infrastructure.
Law enforcement actions under Operation Endgame disrupted DANABOT operations, setting the stage for later malware redevelopment. Subsequent reporting says the malware's authors revised the codebase after these disruptions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.