Fortinet has addressed several critical vulnerabilities affecting its FortiSandbox and FortiWeb products, with public advisories and technical details released on December 16, 2025. The most severe issues impact FortiSandbox, where multiple command injection vulnerabilities (CVE-2025-53949) allow authenticated attackers to execute arbitrary code as root via the admindel_confirm, name, and upload_vdi_file parameters. Additionally, a cross-site scripting vulnerability (CVE-2025-54353) in the hcproxy component could enable remote code execution with minimal user interaction. Fortinet has released patches for these flaws, and users are strongly advised to update affected systems immediately.
For FortiWeb, a critical authentication bypass vulnerability (CVE-2025-64447) was disclosed, stemming from improper verification of cryptographic signatures in the ApacheCookie_parse method, allowing unauthenticated attackers to gain access. These disclosures follow recent reports of active exploitation of a separate FortiWeb vulnerability (CVE-2025-64446), which enables unauthenticated attackers to create rogue administrator accounts and fully compromise exposed devices. Organizations using FortiWeb and FortiSandbox should review the official advisories and apply the recommended mitigations to prevent exploitation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By 2025-12-16, public reporting described how CVE-2025-64446 chained path traversal and authentication bypass issues to reach sensitive CGI scripts and impersonate administrators. Defenders were advised to look for suspicious POST requests, unexpected admin accounts, and anomalous logs.
Following confirmation of active exploitation of CVE-2025-64446, CISA mandated remediation for U.S. federal agencies. The order reflected the risk posed by global scanning and exploitation campaigns targeting vulnerable FortiWeb devices.
On 2025-12-16, Fortinet released updates and coordinated public advisories covering FortiWeb vulnerabilities CVE-2025-64446 and CVE-2025-64447, as well as FortiSandbox vulnerabilities including CVE-2025-53949 and CVE-2025-54353. The advisories urged customers to apply patches immediately due to the severity of the issues.
Jason McFadyen of Trend Research reported the FortiWeb authentication bypass vulnerability CVE-2025-64447 to Fortinet on 2025-10-10. The issue involved improper verification of a cryptographic signature and could let remote attackers bypass authentication without user interaction.
Active exploitation of FortiWeb path traversal vulnerability CVE-2025-64446 began in October 2025, according to reporting cited by watchTowr Labs and confirmed by Fortinet. The flaw allowed unauthenticated attackers to create rogue administrator accounts and take full control of affected devices.
Jason McFadyen of Trend Research reported FortiSandbox command injection vulnerabilities later assigned CVE-2025-53949 to Fortinet in May 2025. The flaws affected multiple endpoints and could allow authenticated attackers to execute code as root.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.