← All CVEs NewScan detects
critical

CVE-2025-64446

FortiWeb path traversal + authentication bypass - crafted HTTP(S) runs administrative commands and creates admin accounts on the WAF itself

Severity
critical
Affected product
FortiWeb
Affected versions
FortiWeb all versions before the fix
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the FortiWeb appliance and reports this CVE when the detected version falls inside the affected range below.

Zero-day; first exploit traffic observed 2025-11-17 (GreyNoise), a persistent edge-device inventory-building campaign. Advisory only - no anonymous version source on the login page.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →