Topic: fortinet fortiweb

  • Active Exploit Targets Suspected FortiWeb Zero-Day

    Active Exploit Targets Suspected FortiWeb Zero-Day

    A critical zero-day vulnerability (CVE-2025-64446) in Fortinet's FortiWeb is being actively exploited, allowing unauthenticated attackers to create unauthorized admin accounts and gain full administrative access. Fortinet silently patched the flaw in multiple versions, including 8.0.2, but delaye...

    Read More »
  • Patch Now: FortiWeb Pre-Auth RCE Exploits Released

    Patch Now: FortiWeb Pre-Auth RCE Exploits Released

    A critical vulnerability (CVE-2025-25257, 9.8/10 severity) in Fortinet's FortiWeb WAF allows unauthenticated remote code execution via SQL injection, requiring immediate patching. Exploits leverage improper SQL sanitization in the Fabric Connector, enabling attackers to inject malicious commands ...

    Read More »