The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical Fortinet FortiWeb vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming that threat actors are actively exploiting the flaw in the wild.
The vulnerability poses an immediate risk to organizations operating Fortinet’s web application firewall (WAF) infrastructure.
Critical Path Traversal Flaw Allows Unauthenticated Admin Access
CVE-2025-64446 is a severe relative path-traversal vulnerability in Fortinet FortiWeb that enables unauthenticated attackers to gain administrative access to affected systems.
The security flaw is classified as CWE-23 (Relative Path Traversal), a weakness that occurs when software fails to validate and neutralize special path elements in external input properly.
This oversight allows attackers to traverse outside restricted directories and access protected files and resources.
Threat actors can exploit this vulnerability by sending specially crafted HTTP or HTTPS requests directly to vulnerable FortiWeb devices.
The attack requires no authentication, making it particularly dangerous for exposed or internet-facing deployments.
Once attackers achieve administrative access, they can execute commands on the compromised WAF with full privileges, creating significant operational risk for protected applications and downstream infrastructure.
CISA added CVE-2025-64446 to the KEV catalog on November 14, 2025, signaling confirmed active exploitation.
Federal agencies operating under Binding Operational Directive (BOD) 22-01 face a critical remediation deadline of November 21, 2025, just seven days from the advisory.
While BOD 22-01 mandates explicit action for Federal Civilian Executive Branch agencies, CISA strongly recommends that all organizations prioritize patching to reduce cyber risk exposure.
The ability to compromise FortiWeb devices carries significant consequences beyond the immediate system.
A successful exploitation could grant attackers deep visibility into protected applications, enable them to disable security controls, intercept sensitive data passing through the WAF, and pivot laterally into other systems within corporate networks.
While CISA has not confirmed whether CVE-2025-64446 is being exploited in ransomware campaigns, the vulnerability’s ability to grant administrative access makes it an attractive target for ransomware operators seeking initial network access.
Organizations using Fortinet FortiWeb should immediately take action.
The three primary remediation options include applying security patches per Fortinet’s vendor instructions, implementing applicable BOD 22-01 guidance for cloud services, or discontinuing use of affected products if vendor mitigations remain unavailable.
System administrators should review access logs for suspicious HTTP/HTTPS requests indicating exploitation attempts and implement network segmentation to limit lateral movement if a compromise occurs.
The tight remediation timeline and confirmed active exploitation underscore the severity of this threat.
Organizations must treat this vulnerability as an urgent priority and complete patching before the November 21 deadline.
| CVE ID | Vendor | Product | Vulnerability Type | CVSS Score | CWE | Authentication Required | Active Exploitation | Remediation Deadline |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-64446 | Fortinet | FortiWeb WAF | Path Traversal | Critical | CWE-23 | No | Yes | November 21, 2025 |
Find this Story Interesting! Follow us on Google News, LinkedIn and X to Get More Instant Updates