Fortinet has confirmed that it has silently patched a critical zero-day vulnerability in its FortiWeb web application firewall, which is now "massively exploited in the wild." The flaw was silently patched after reports that unauthenticated attackers were exploiting an unknown FortiWeb path traversal flaw in early October to create new administrative users on Internet-exposed devices. The attacks were first identified by threat intel firm Defused on October 6, which published a proof-of-concept exploit and reported that an "unknown Fortinet exploit (possibly a CVE-2022-40684 variant)" is being used to send HTTP POST requests to the /api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi Fortinet endpoint to create local admin-level accounts. On Thursday, watchTowr Labs security researchers also demoed an exploit and released a tool called "FortiWeb Authentication Bypass Artifact Generator to help defenders identify vulnerable devices. Cybersecurity firm Rapid7 added that the flaw affects FortiWeb versions 8.0.1 and earlier, as it confirmed that the publicly available proof-of-concept exploit no longer works after updating to version 8.0.2. Today, Fortinet disclosed that attackers are actively exploiting a path confusion vulnerability (now tracked as CVE-2025-64446) in FortiWeb's GUI component, which allows unauthenticated attackers to execute administrative commands on unpatched systems via crafted HTTP or HTTPS requests. "Fortinet has observed this to be exploited in t...
Fortinet confirms silent patch for FortiWeb zero-day exploited in attacks
BleepingComputer
·Sergiu Gatlan
·Published Nov 14, 2025
·Updated
Affected Software
1 affected component
Fortinet FortiWeb
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical zero-day vulnerability in Fortinet's FortiWeb web application firewall that has been exploited in attacks.
2
What action did Fortinet take regarding the zero-day vulnerability?
Fortinet silently patched the zero-day vulnerability to mitigate ongoing exploitation in the wild.
3
How serious is the vulnerability mentioned in the article?
The vulnerability is described as critical and has been massively exploited in real-world attacks.
4
What product is affected by the security issue discussed in the article?
The affected product is Fortinet's FortiWeb web application firewall.
5
What should users of FortiWeb do in light of this zero-day patch?
Users of FortiWeb should ensure their systems are updated with the latest patch to protect against the exploitation of the vulnerability.