As cited
Copy frozen at (site build).
vulnerabilities
FortiWeb CVE‑2025‑64446: What We’re Seeing in the Wild
GreyNoise has detected active exploitation of CVE-2025-64446, a critical path-traversal vulnerability in Fortinet FortiWeb that allows unauthenticated attackers to execute administrative commands on affected appliances. The flaw is being actively exploited in the wild against internet-facing FortiWeb instances.
Why it matters: Organizations running FortiWeb appliances face immediate risk from unauthenticated remote code execution attacks; patching or applying mitigations should be prioritized today.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
FortiWeb CVE‑2025‑64446: What We’re Seeing in the Wild
GreyNoise has detected active exploitation of CVE-2025-64446, a critical path-traversal vulnerability in Fortinet FortiWeb that allows unauthenticated attackers to execute administrative commands on affected appliances. The flaw is being actively exploited in the wild against internet-facing FortiWeb instances.
Why it matters: Organizations running FortiWeb appliances face immediate risk from unauthenticated remote code execution attacks; patching or applying mitigations should be prioritized today.
- Source published
- First seen by Cybersecurity Tracker