← All CVEs NewScan detects
critical

CVE-2025-64446

FortiWeb path traversal + authentication bypass - crafted HTTP(S) runs administrative commands and creates admin accounts on the WAF itself

Severity
critical
Affected product
FortiWeb
Affected versions
FortiWeb all versions before the fix
Detection basis
Appliance fingerprint
Shipped rule
FortiWeb: FortiWeb path traversal + authentication bypass - crafted HTTP(S) runs administrative commands and creates admin accounts on the WAF itself
Added to NewScan
2026-08-06
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the FortiWeb appliance and reports this CVE when the detected version falls inside the affected range below.

Zero-day; first exploit traffic observed 2025-11-17 (GreyNoise), a persistent edge-device inventory-building campaign. Advisory only - no anonymous version source on the login page.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →

Review the measured benchmark, then use the verified remediation process.