Fortinet patched a high-severity authentication bypass flaw in FortiWeb tracked as CVE-2025-52970, which can allow a remote unauthenticated attacker to obtain administrator privileges under certain conditions. The vulnerability stems from improper validation and processing of the Era parameter in cookies, which can cause the server to use a null secret key for session encryption and HMAC signing, enabling forged authenticated sessions.
Affected versions are FortiWeb 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, and 7.0.0 through 7.0.10. The flaw carries a CVSS v3.1 score of 7.7, and Fortinet has released fixes in 7.6.4, 7.4.8, 7.2.11, and 7.0.11 and later, with guidance to upgrade immediately to prevent unauthorized administrative access.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Fortinet released fixes for a high-severity FortiWeb authentication bypass flaw tracked as CVE-2025-52970. The issue affects multiple FortiWeb versions and can allow a remote unauthenticated attacker to gain administrator privileges by manipulating the Era cookie parameter.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.