Start with Identity
Identity CVE · Other

CVE-2025-64446FortiWeb auth bypass and path traversal, admin creation

critical · CVSS 9.8CISA KEVActively exploited
Product: Fortinet FortiWebVendor: FortinetCWE-288Disclosed: 2025-11-14Status: Actively exploitedNVD ↗CISA KEV ↗

What broke

FortiWeb had an authentication bypass combined with path traversal that let an unauthenticated attacker create an administrative user. CVSS 9.8. CISA added it to KEV around 14 November 2025.

Why it matters

This is not a SAML bug. It is a management-plane auth bypass on the same product family that later failed FortiCloud SSO. Two independent ways to become admin on a WAF, both exploited, both on KEV, is a pattern: the identity of the appliance is the target, not a single protocol.

What to do

  • Patch FortiWeb for CVE-2025-64446 and then take the SSO fixes (CVE-2025-59719, CVE-2026-24858).
  • Hunt for admin accounts that were not created by your change process, especially from mid-November 2025.
  • Take FortiWeb management off the internet. Put it behind a jump path with phishing-resistant MFA.

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.