CVE-2025-64446Active Exploitation(fortinet / fortiweb)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet fortiweb systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-11-21. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-23

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortiweb

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 12 mentions across 12 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • General: 2 classified signals
  • Peaked 11d ago at 1 mentions (2026-02-11); latest day: 1
  • 12 total mentions across 12 days

Affected systems

Vendors
Products
fortiweb

Deep dive

Activity timeline12 mentions / 12d
00111Mentions · 2026-02-11: 1Mentions · 2026-02-12: 1Mentions · 2026-02-18: 1Mentions · 2026-03-13: 1Mentions · 2026-04-08: 1Mentions · 2026-04-12: 1Mentions · 2026-04-18: 1Mentions · 2026-07-05: 1Mentions · 2026-07-06: 1Mentions · 2026-07-08: 1Mentions · 2026-07-20: 1Mentions · 2026-09-27: 1PoC Mentioned / Linked · 2026-07-05: 1PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-08: 1PoC Mentioned / Linked · 2026-07-20: 1Exploit Tool / Code · 2026-07-20: 1Active Exploitation · 2026-02-11: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-07-20: 1Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-02-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-04-18: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-20: 102-1102-1202-1803-1304-0804-1204-1807-0507-0607-0807-2009-27
Signal classification5 categories
Active Exploitation
327.3%
PoC
327.3%
General
218.2%
Patch
218.2%
Disclosure
19.1%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-111
Active Exploitation1
2026-02-121
General1
2026-02-181
General1
2026-03-131
Disclosure1
2026-04-081
Active Exploitation1
2026-04-121
Patch1
2026-04-181
Patch1
2026-07-051
PoC1
2026-07-061
PoC1
2026-07-081
PoC1
2026-07-201
Active Exploitation1
Full discourse12 posts
  • Germán Fernández@1ZRR4H
    General

    🚩 Vibe coding + FortiWeb exploitation platform (CVE-2025-64446 ⛓️ CVE-2025-58034) + C2 server (?) + #opendir (now off) 💀🤷🏻‍♂️ https://t.co/SUjGlZfpVZ

    Post summary

    The tweet references two FortiWeb CVEs and suggests a potential exploitation platform with an uncertain C2 server, but it lacks specific technical, patch, or active exploitation details.

    113422019723.7K
    36.9K followersView on X
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    The tweet enumerates the top 25 CVE exploitation attempts identified by Team Cymru, showing active exploitation of those vulnerabilities over a 14‑day period.

    070921.2K
    5.5K followersView on X
  • Crowdfense@crowdfense
    General

    The following vulnerabilities have been added to our feed: - CVE-2025-64446: Fortinet Fortiweb Command Injection RCE - CVE-2025-62221: Microsoft Cloud Files Mini Filter Driver UAF LPE - CVE-2025-26666: Windows Media Heap-based Buffer Overflow DoS https://www.crowdfense.com/n-day-feed/

    Post summary

    The feed lists three CVEs with brief vulnerability type descriptors, offering no deeper technical details, exploit availability, or mitigation information.

    00055808
    2.9K followersView on X
  • reverseame@reverseame
    Disclosure

    When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb Auth. Bypass CVE-2025-64446) #FortiWeb #AuthBypass #CVE202564446 #PathTraversal #Impersonation https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/

    Post summary

    An authentication bypass flaw (CVE-2025-64446) in Fortinet FortiWeb is disclosed, involving path traversal and user impersonation possibilities.

    01070979
    21.8K followersView on X
  • Cedric Blandamour@CedricBldmr

    @DailyDarkWeb The forum post says "1-day exploit for Fortinet Fortiweb", apparently on versions 8.0 and 8.1 chaining 2 CVEs. This could be linked to CVE-2025-64446 + CVE-2025-58034 chaining. Why does your text mentions "Fortinet Fortigate SSL VPN" and "7.2.x and 7.4.x" ?

    10010146
    192 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    PoC

    لباحثين رصدوا على الأقل 7 مستودعات PoC تنشر ChocoPoC، وكانت تستغل أسماء ثغرات مغرية مثل: 📍 FortiWeb CVE-2025-64446 📍 React2Shell CVE-2025-55182 📍 MongoBleed CVE-2025-14847 📍 PAN-OS CVE-2026-0257

    Post summary

    Researchers discovered multiple PoC repositories (ChocoPoC) that include severe CVEs such as FortiWeb CVE‑2025‑64446, React2Shell CVE‑2025‑55182, MongoBleed CVE‑2025‑14847, and PAN‑OS CVE‑2026‑0257.

    10010141
    49.3K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    CVE-2025–64446: FortiWeb Authentication bypass PoC https://www.silvasec.seg.br/poc-cve-2025-64446-fortiweb-authentication-bypass-76d009dc94a1

    Post summary

    The tweet announces CVE-2025–64446, providing a proof-of-concept for an authentication-bypass flaw in FortiWeb with a link to the code, but it lacks exploitation details, patch info, or evidence of active attacks.

    01000269
    1.2K followersView on X
  • BBWriteup@bbwriteup
    PoC

    "PoC — CVE-2025–64446: FortiWeb Authentication bypass" by Jonathan M. #InfoSec #CyberSecurity #Hacking #BugBounty https://medium.com/@silvasec/poc-cve-2025-64446-fortiweb-authentication-bypass-76d009dc94a1

    Post summary

    A proof‑of‑concept for CVE‑2025‑64446, an authentication bypass flaw in FortiWeb, is shared via a Medium post.

    00010170
    760 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 FortiWeb Impersonation Flaw: How #CVE-2025-64446 Lets Attackers Become Any User – And How To Stop It + Video https://undercodetesting.com/fortiweb-impersonation-flaw-how-cve-2025-64446-lets-attackers-become-any-user-and-how-to-stop-it-video/ Educational Purposes!

    Post summary

    The tweet points to an article that explains the FortiWeb impersonation flaw (CVE-2025-64446) and offers mitigation steps.

    00010472
    497 followersView on X
  • BT Haberler@BTHaberler
    Active Exploitation

    Bir CVE için exploit ararken indirdiğiniz "PoC" kodu, sizi hedef alan bir RAT olabilir! YesWeHack ve Sekoia, GitHub'da CVE-2025-64446, CVE-2026-50751 gibi popüler açıklar için sahte PoC exploitleri yayınlayan ChocoPoC kampanyasını keşfetti. Sahte PoC, frint ve skytext bağımlılıklarını indirerek gerçek RAT'ı devreye sokuyor. • Chrome, Brave, Edge ve Firefox'tan şifre, çerez ve otomatik doldurma verileri çalınıyor; keyfi Python kodu çalıştırılabiliyor. • skytext paketi yaklaşık 2.400 kez indirildi; kampanya 2025 sonundan beri aktif. • C2 iletişimi için Mapbox veri seti ve DNS-over-HTTPS kullanılıyor; İspanyolca konuşan operatörlere işaret eden izler var. Güvenlik araştırmacıları bile hedef — bir exploit PoC'sini çalıştırmadan önce izole bir ortamda inceleyin! #SiberGüvenlik #ChocoPoC #RAT

    Post summary

    ChocoPoC revealed that fake PoC exploits for CVE‑2025‑64446 and CVE‑2026‑50751 are actively used in the wild, deploying a RAT that steals credentials and can run arbitrary Python code.

    0000053
    36 followersView on X
  • breachwire.io@breachwire_io
    Patch

    Critical Fortinet FortiWeb flaws in older versions pose security risks beyond CVE-2025-64446 & CVE-2025-5034. Prioritize immediate updates. #CIO #DigitalRiskManagement https://www.cybersecuritydive.com/news/fortinet-fortiweb-flaws-found-in-unsupported-versions-of-web-application-fi/806791/

    Post summary

    The post highlights that older Fortinet FortiWeb versions contain critical flaws beyond CVE‑2025‑64446 and CVE‑2025‑5034, urging immediate updates.

    00000171
    13 followersView on X
  • breachwire.io@breachwire_io
    Active Exploitation

    Monitor CVE-2025-64446 exploit attempts with honeypots. Stay vigilant to protect your systems. #CISO #CyberSecurity https://isc.sans.edu/diary/rss/32486

    Post summary

    The post highlights ongoing exploitation attempts of CVE‑2025‑64446 and recommends monitoring with honeypots to protect systems.

    0000054
    13 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfortinetfortiweb---

Explore more