critical
CVE-2025-64446
FortiWeb path traversal + authentication bypass - crafted HTTP(S) runs administrative commands and creates admin accounts on the WAF itself
- Severity
- critical
- Affected product
- FortiWeb
- Affected versions
- FortiWeb all versions before the fix
- Added to NewScan
- 2026-08-06
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the FortiWeb appliance and reports this CVE when the detected version falls inside the affected range below.
Zero-day; first exploit traffic observed 2025-11-17 (GreyNoise), a persistent edge-device inventory-building campaign. Advisory only - no anonymous version source on the login page.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →