Fortinet customers told to update immediately following major security issue – here’s what we know



  • CVE-2025-64446 allows unauthenticated attackers to run admin commands on FortiWeb WAF systems
  • Actively exploited in the wild; affects versions 7.0.0–8.0.1, patched in 8.0.2
  • CISA added it to KEV; Fortinet urges immediate patching or disabling internet-facing HTTP/HTTPS interfaces

Fortinet has released a fix for a critical vulnerability in its FortiWeb web application firewall (WAF), and has urged customers to update immediately, as the flaw is being actively exploited in the wild.

The company published a new security advisory, saying it addressed a relative path traversal vulnerability that allows unauthenticated threat actors to execute administrative commands on the system.


https://cdn.mos.cms.futurecdn.net/LUvpjsYFmoug6huuzFtM4m-2355-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img