CVE-2025-53609: Fortinet FortiWeb
Medium severity, CVSS 4.9. EPSS: 9.3% chance of exploitation in the next 30 days.
A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests.
Affected products
- Fortinet FortiWeb: from 7.0.2, before 7.2.12 (fixed in 7.2.12); from 7.4.0, before 7.4.9 (fixed in 7.4.9); from 7.6.0, before 7.6.5 (fixed in 7.6.5)
Published 2025-09-09. Last modified 2026-06-17.