Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Warns of Fortinet FortiWeb WAF Vulnerability Exploited in the Wild to Gain Admin Access

CISA Warns of Fortinet FortiWeb WAF Vulnerability Exploited in the Wild to Gain Admin Access

Posted on November 17, 2025November 17, 2025 By CWS

CISA has issued an pressing alert a few important vulnerability in Fortinet’s FortiWeb Net Software Firewall (WAF), actively exploited by menace actors to grab administrative management of affected techniques.

Tracked as CVE-2025-64446, the flaw stems from a relative path traversal challenge (CWE-23) that allows unauthenticated attackers to execute arbitrary administrative instructions by way of specifically crafted HTTP or HTTPS requests.

Added to CISA’s Identified Exploited Vulnerabilities (KEV) catalog on November 14, 2025, the vulnerability carries a due date of November 21 for federal businesses to use mitigations or discontinue use.

Fortinet’s advisory (FG-IR-25-910) confirms the difficulty impacts a number of FortiWeb variations, together with these working firmware as much as 7.4.7 and seven.6.5. Attackers can exploit it with out authentication, probably main to finish system compromise, knowledge exfiltration, or deployment of malware.

Whereas it’s unknown whether or not the vulnerability has been tied to ransomware campaigns, safety researchers have reported real-world exploitation within the wild concentrating on organizations in sectors like finance and healthcare.

FortiWeb WAF Vulnerability Exploited within the Wild

“This path traversal bug is a basic however harmful oversight in file dealing with,” mentioned cybersecurity skilled Maria Chen, a vulnerability researcher at a number one menace intelligence agency. “Unauthenticated entry to admin features turns a WAF meant to guard internet apps right into a backdoor for attackers.”

Fortinet urges instant patching to the newest variations, corresponding to 7.4.8 or 7.6.6, and recommends limiting administrative entry through community segmentation.

For cloud-deployed situations, CISA advises adherence to Binding Operational Directive (BOD) 22-01, which mandates well timed remediation of vulnerabilities in federal techniques.

Organizations unable to patch ought to isolate affected gadgets and monitor for indicators of compromise, corresponding to uncommon HTTP site visitors patterns or unauthorized command execution.

The flaw highlights ongoing dangers in community safety home equipment, that are prime targets for superior persistent threats (APTs). As exploitation ramps up, specialists warn that unpatched FortiWeb deployments may amplify broader assault chains, corresponding to lateral motion in enterprise networks. Fortinet has not disclosed the preliminary discovery methodology however emphasizes that no buyer knowledge was breached throughout its investigation.

With the patch deadline looming, affected customers are racing to replace. Delays may expose delicate infrastructure to persistent threats, underscoring the necessity for proactive vulnerability administration in an period of zero-day exploits.

Observe us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Access, Admin, CISA, Exploited, Fortinet, FortiWeb, Gain, Vulnerability, WAF, Warns, Wild

Post navigation

Previous Post: DoorDash Says Personal Information Stolen in Data Breach
Next Post: Hackers Leverages Microsoft Entra Tenant Invitations to Launch TOAD Attacks

Related Posts

Betterment Breach Affects 1.4 Million Accounts Betterment Breach Affects 1.4 Million Accounts Cyber Security News
DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments Cyber Security News
OpenAI Launches  ChatGPT Go Plan with Unlimited Access to GPT-5 OpenAI Launches $4 ChatGPT Go Plan with Unlimited Access to GPT-5 Cyber Security News
New Ransomware Threats BQTLock and GREENBLOOD Emerge New Ransomware Threats BQTLock and GREENBLOOD Emerge Cyber Security News
Securing Multi-Cloud Infrastructures in 2025 Enterprise Deployments Securing Multi-Cloud Infrastructures in 2025 Enterprise Deployments Cyber Security News
NVIDIA Container Toolkit Vulnerability Allows Elevated Arbitrary Code Execution NVIDIA Container Toolkit Vulnerability Allows Elevated Arbitrary Code Execution Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News