Fortinet customers told to update immediately following major security issue – here’s what we know

  • CVE-2025-64446 allows unauthenticated attackers to run admin commands on FortiWeb WAF systems
  • Actively exploited in the wild; affects versions 7.0.0–8.0.1, patched in 8.0.2
  • CISA added it to KEV; Fortinet urges immediate patching or disabling internet-facing HTTP/HTTPS interfaces

Fortinet has released a fix for a critical vulnerability in its FortiWeb web application firewall (WAF), and has urged customers to update immediately, as the flaw is being actively exploited in the wild.

The company published a new security advisory, saying it addressed a relative path traversal vulnerability that allows unauthenticated threat actors to execute administrative commands on the system.

The bug is now tracked as CVE-2025-64446 and was given a severity score of 9.8/10, meaning it’s critical and that it should be addressed promptly.

Abusing the zero-day

The bug affects multiple versions of the WAF:

8.0.0 through 8.0.1,

7.6.0 through 7.6.4,

7.4.0 through 7.4.9,

7.2.0 through 7.2.11,

7.0.0 through 7.0.11

It was fixed in version 8.0.2, security researchers confirmed.

The fix should be applied without hesitation, Fortinet added, stating that the bug was “observed to be exploited in the wild.”

Indeed, it is, as multiple security outfits have been warning about this one for weeks. In early October 2025, security researchers from Defused published a Proof-of-Concept (PoC) for an “unknown Fortinet exploit”, followed by a demo exploit published by watchTowr Labs.

Those that cannot apply the fix immediately should disable HTTP or HTTPS for internet-facing interfaces, Fortinet advised. “If the HTTP/HTTPS Management interface is internally accessible only as per best practice, the risk is significantly reduced.” Also, after patching, users should review their configuration for and review logs for unexpected modifications, and to see if any new admin accounts were added.

The bug was also added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, meaning federal agencies have until November 21 to patch or stop using Fortinet’s WAF.

“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA warned.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

The Clapper was a bad smart home gadget — and a viral sensation

Clap on. Clap off. Well, more like, Clap, pause for half a beat but no longer because otherwise it'll stop hearing you, clap again...

US Marshals arrest the Tate brothers in Miami

Andrew and Tristan Tate talk to the media on March 23, 2025 in Romania. | Image: Andrei Pungovschi/Getty Images The manosphere influencers Andrew and Tristan...

Birdfy’s solar-powered smart feeder is down to one of its best prices

It comes with a solar panel so you don’t need to worry about charging as much during the summer. | Image: Netvue Birdfy has kicked...

Orchid is a delightfully retro and approachable hipster synth

A modern tribute to electric chord organs which were basically giant harmonicas connected to a fan. | Photo: Terrence O’Brien / The Verge In 2017,...

OnePlus died with a whimper, not a bang

OnePlus is dead – actually for real this time. It’s got me looking back on my experiences with the brand’s smartphones, the absolute roller...

The grueling, 630-mile road race where the only fuel is sunlight

The 2018 Solar Car Challenge was the last time participants took their designs out on the open road. | Image: Lehman Marks / Solar...

The future of physical games is not looking great

Grand Theft Auto VI release won’t offer a disc. | Image: Rockstar Games This is The Stepback, a weekly newsletter breaking down one essential story...

Dave Eggers told OpenAI staff that ChatGPT was ‘silencing an entire generation’

Dave Eggers attends the "The Turning Point: To Be Destroyed" premiere. | Image: John Lamparski/Getty Images for Tribeca Festival Last year, Sam Altman invited author...

YouTube picture-in-picture (PiP) mode is broken on iPhone, Android

YouTube is aware of an issue on Android and iPhone where picture-in-picture (PiP) mode does not activate when closing the app. Read more @ 9to5google

Galaxy Watch 9 is ‘Powered by Snapdragon Wear Elite,’ leaked images confirm [Gallery]

As expected, Samsung is switching its new Galaxy Watch 9 over to a Qualcomm chip, the Snapdragon Wear Elite, as some new images confirm....