Fortinet Customers Asked to Update Immediately After Major Security Issue – Here’s What We Know



  • CVE-2025-64446 allows unauthenticated attackers to execute administration commands on FortiWeb WAF systems
  • Actively exploited in the wild; affects versions 7.0.0–8.0.1, patched in 8.0.2
  • CISA added it to KEV; Fortinet urges immediate patching or disabling of HTTP/HTTPS interfaces connected to the Internet

Fortinet has released a fix for a critical vulnerability in its FortiWeb web application firewall (WAF) and has urged customers to update immediately as the flaw is being actively exploited in the wild.

The company published a new security advisory, saying it addressed a relative path traversal vulnerability that allows unauthenticated threat actors to execute administrative commands on the system.



Leave a Comment

Your email address will not be published. Required fields are marked *