CVE-2025-64446 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 91.8% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2025-11-21.
Description
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 91.84% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-23 |
| On CISA KEV | yes — remediate by 2025-11-21 |
| Public exploit | yes |
| Published | 2025-11-14 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Fortinet FortiWeb Path Traversal Vulnerability |
|---|---|
| Added | 2025-11-14 |
| Due | 2025-11-21 |
| Vendor / product | Fortinet / FortiWeb |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| fortinet | fortiweb |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | FortiWeb 8.0.2 - Remote Code Execution | 2026-04-08 |
| exploit-db | Fortinet FortiWeb v8.0.1 - Auth Bypass | 2026-04-06 |
References
→ the Explorer · watch your stack · NVD