CVE-2025-64446: Fortinet FortiWeb Path Traversal Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-11-14. EPSS: 91.8% chance of exploitation in the next 30 days.

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

Affected products

  • Fortinet FortiWeb: from 7.0.0, before 7.0.12 (fixed in 7.0.12); from 7.2.0, before 7.2.12 (fixed in 7.2.12); from 7.4.0, before 7.4.10 (fixed in 7.4.10); from 7.6.0, before 7.6.5 (fixed in 7.6.5); from 8.0.0, before 8.0.2 (fixed in 8.0.2)

Published 2025-11-14. Last modified 2026-06-17.