• News/
  • https://www.bleepingcomputer.com/news/security/fortinet-confirms-silent-patch-for-fortiweb-zero-day-exploited-in-attacks/

Fortinet confirms silent patch for FortiWeb zero-day exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Nov 14, 2025
·
Updated

Fortinet has confirmed that it has silently patched a critical zero-day vulnerability in its FortiWeb web application firewall, which is now "massively exploited in the wild." The flaw was silently patched after reports that unauthenticated attackers were exploiting an unknown FortiWeb path traversal flaw in early October to create new administrative users on Internet-exposed devices. The attacks were first identified by threat intel firm Defused on October 6, which published a proof-of-concept exploit and reported that an "unknown Fortinet exploit (possibly a CVE-2022-40684 variant)" is being used to send HTTP POST requests to the /api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi Fortinet endpoint to create local admin-level accounts. On Thursday, watchTowr Labs security researchers also demoed an exploit and released a tool called "FortiWeb Authentication Bypass Artifact Generator to help defenders identify vulnerable devices. Cybersecurity firm Rapid7 added that the flaw affects FortiWeb versions 8.0.1 and earlier, as it confirmed that the publicly available proof-of-concept exploit no longer works after updating to version 8.0.2. Today, Fortinet disclosed that attackers are actively exploiting a path confusion vulnerability (now tracked as CVE-2025-64446) in FortiWeb's GUI component, which allows unauthenticated attackers to execute administrative commands on unpatched systems via crafted HTTP or HTTPS requests. "Fortinet has observed this to be exploited in t...

Read full article

Affected Software

1 affected component
Fortinet FortiWeb

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical zero-day vulnerability in Fortinet's FortiWeb web application firewall that has been exploited in attacks.

2

What action did Fortinet take regarding the zero-day vulnerability?

Fortinet silently patched the zero-day vulnerability to mitigate ongoing exploitation in the wild.

3

How serious is the vulnerability mentioned in the article?

The vulnerability is described as critical and has been massively exploited in real-world attacks.

4

What product is affected by the security issue discussed in the article?

The affected product is Fortinet's FortiWeb web application firewall.

5

What should users of FortiWeb do in light of this zero-day patch?

Users of FortiWeb should ensure their systems are updated with the latest patch to protect against the exploitation of the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203