Cyberdaily.Au
Critical Vulnerabilities in Fortinet FortiWeb Actively Exploited
First seen 1 Dec 2025, 15:41 UTC
•



+31
•33.1
Export
Article Content
Browse articles
Fortinet's FortiWeb web application firewall has been compromised by two critical vulnerabilities, CVE-2025-64446 and CVE-2025-58034, both of which are under active exploitation. The first vulnerability allows unauthenticated attackers to execute administrative commands, while the second enables authenticated attackers to perform OS command injection. CISA has issued urgent advisories for affected organizations to patch their systems promptly.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Cisco SD-WAN Zero-Day Exploited by Threat Actor Since 2023
FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation
Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild
Escalating Cyber Warfare Threats Amid Geopolitical Tensions
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
Red Menshen APT Uses BPFdoor for Long-Term Espionage in Telecom Networks