https://labs.watchtowr.com/when-the-impersonation-function-gets-used-to-impersonate-users-fortinet-fortiweb-auth-bypass/
The Internet is ablaze, and once again we all have a front-row seat - a bad person, if you can believe it, is doing a bad thing! The first warning of such...
impersonationfunctiongetsusedimpersonate
https://azure.fortiweb-cloud.com/
FortiWeb, Fortinet’s Web Application Firewall, protects your business-critical web applications from attacks that target known and unknown vulnerabilities.
try freefortiwebazure
https://www.rapid7.com/blog/post/etr-critical-vulnerability-in-fortinet-fortiweb-exploited-in-the-wild/
On October 6, 2025, the cyber deception company Defused published a proof-of-concept exploit on social media that was captured by one of their Fortinet...
critical vulnerabilityfortinetfortiwebexploitedwild
https://niebezpiecznik.pl/post/krytyczna-luka-w-fortinet-fortiweb-uzywana-do-atakow-paczujcie-sie/
lukawfortinet
https://www.greenbone.net/en/blog/a-lurking-fortiweb-vulnerability-proves-critical-amid-active-exploitation/
Nov 18, 2025 - FortiWeb faces a critical vulnerability ⚡ Greenbone provides accurate detection and protection for CVE-2025-64446.
fortiwebexploitcvecriticalthreat
https://www.techzine.eu/news/security/136523/fortinet-hit-again-by-zero-day-vulnerability-in-fortiweb/
Nov 20, 2025 - Fortinet is under fire after the discovery of a second zero-day vulnerability in FortiWeb within a week. The company has released an update.
zero dayfortinethitvulnerabilityfortiweb
https://kyberturvallisuuskeskus.fi/fi/haavoittuvuus_22/2025
Fortinet julkaisi haavoittuvuustiedotteen FortiWeb-tuotteisiin vaikuttavasta haavoittuvuudesta, joka voi mahdollistaa todentamattoman hyökkääjän suorittaa...
jafortinetfortiweb
https://horizon3.ai/attack-research/vulnerabilities/cve-2025-64446/
Nov 17, 2025 - Critical FortiWeb flaw (CVE-2025-64446) allows unauthenticated admin creation and full takeover. Active exploitation observed—patch and restrict...
fortinetfortiwebauthbypasscve
https://www.patrowl.io/en/actualites/fortithing-a-classic-friday
A FortiWeb exploit is circulating with no official CVE. Learn how to instantly detect exposed instances and prioritize real actions without the usual chaos.
fortiwebnewcriticalflawfast
https://www.bleepingcomputer.com/news/security/fortinet-warns-of-new-fortiweb-zero-day-exploited-in-attacks/
Today, Fortinet released security updates to patch a new FortiWeb zero-day vulnerability that threat actors are actively exploiting in attacks.
zero dayfortinetwarnsnewfortiweb
https://www.bitsight.com/blog/critical-vulnerability-alert-cve-2025-64446-fortinet-fortiweb-vulnerability
A critical vulnerability, CVE-2025-64446, in Fortinet FortiWeb is being actively exploited. Read more for technical details & impact to organizations.
next stepscvefortinetfortiwebdetails