peter bassill · operator
$ cve CVE-2025-64446 JSON

CVE-2025-64446 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 91.8% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-11-21.

Description

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS91.84% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-23
On CISA KEVyes — remediate by 2025-11-21
Public exploityes
Published2025-11-14
Last modified2026-06-17

CISA KEV

NameFortinet FortiWeb Path Traversal Vulnerability
Added2025-11-14
Due2025-11-21
Vendor / productFortinet / FortiWeb
Ransomware usenone reported

Affected (1)

VendorProduct
fortinetfortiweb

Public exploits

SourceTitleDate
exploit-dbFortiWeb 8.0.2 - Remote Code Execution2026-04-08
exploit-dbFortinet FortiWeb v8.0.1 - Auth Bypass2026-04-06

References

→ the Explorer  ·  watch your stack  ·  NVD