A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
Published: 2025-11-14
CVE-2025-64446 FortiWeb Zero-Day Exploited in the wild
https://www.darkreading.com/vulnerabilities-threats/fortinet-emergency-patch-forticlient-zero-day
https://research.checkpoint.com/2026/sicarii-ransomware-truth-vs-myth/
https://www.theregister.com/2025/11/19/fortinet_confirms_second_fortiweb_0day/
https://www.securityweek.com/fortinet-discloses-second-exploited-fortiweb-zero-day-in-a-week/
https://www.hipaajournal.com/fortinet-patches-actively-exploited-fortiweb-zero-day-flaw/
https://www.helpnetsecurity.com/2025/11/19/fortiweb-vulnerability-cve-2025-58034/
https://thehackernews.com/2025/11/fortinet-warns-of-new-fortiweb-cve-2025.html
https://therecord.media/fortinet-fortiweb-vulnerability-cisa-advisory
https://www.fortiguard.com/psirt/FG-IR-25-910
https://thehackernews.com/2025/11/fortinet-fortiweb-flaw-actively.html
https://github.com/CerberusMrXi/FortiWeb-cve-2025-64446-RCE-exploit
https://github.com/litndat/Vulnerability-CVE-2025-64446-CVE-2025-58034
https://github.com/MohammedAbdulAhadSaud/DotSlash
https://github.com/0xBlackash/CVE-2025-64446
https://github.com/0xAshwesker/CVE-2025-64446
https://github.com/eagle-nett/FORTIWEB_CVE-2025-64446-58034
https://github.com/mrbz-sec01/FortiWeb-CVE
https://github.com/BaoSec/FortiWeb-CVE
https://github.com/BaoSec/CVE-2025-64446-CVE-2025-58034-Research-and-Analysis
https://github.com/tralsesec/AnatomyOfABug
https://github.com/lequoca/fortinet-fortiweb-cve-2025-64446-58034
https://github.com/32BitZ-Studio/Total-POC-CVE
https://github.com/Death112233/CVE-2025-64446-
https://github.com/B1ack4sh/Blackash-CVE-2025-58034
https://github.com/lincemorado97/CVE-2025-64446_CVE-2025-58034
https://github.com/lincemorado97/CVE-2025-64446
https://github.com/D3crypT0r/CVE-2025-64446
https://github.com/sensepost/CVE-2025-64446
https://github.com/soltanali0/CVE-2025-64446-Exploit
https://github.com/B1ack4sh/Blackash-CVE-2025-64446
https://github.com/sxyrxyy/CVE-2025-64446-FortiWeb-CGI-Bypass-PoC
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-64446
Published: 2025-11-14
Updated: 2025-11-21
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.91838
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest