Fortinet FortiWeb Authentication Bypass – CVE-2025-64446
bishopfox.com | vulnerability | Critical | Actively exploited | CVE-2025-64446 | #active-exploitation | #vulnerability-research | #authentication-bypass | #web-security | #scanner | #fortiweb | #cve-2025-64446 | #cisa-kev
Summary
Bishop Fox confirms CVE-2025-64446: one HTTP POST with a path traversal and crafted header creates an admin account on vulnerable FortiWeb builds, giving device takeover; CISA KEV listed.
- CVSS
- 9.8
- Published
- Collected
Skip to content