CVE-2025-64446 is a vulnerability tracked across 11 threat clusters and 37 intelligence report mentions on ThreatCluster. First observed November 14, 2025; most recent activity July 2, 2026.
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
A coordinated supply chain attack has been identified, targeting vulnerability researchers and penetration testers through malicious proof-of-concept (PoC) repositories on GitHub. The malware, named ChocoPoC, is a…
CVE-2025-64756 identifies a command injection vulnerability in the glob CLI affecting versions 10.3.7 to 11.0.3. CVE-2025-64446 reveals a relative path traversal vulnerability in Fortinet FortiWeb versions 8.0.0 to…
More than 10,000 Fortinet firewalls remain exposed to a critical two-factor authentication bypass vulnerability (CVE-2020-12812) that has been actively exploited. This flaw, first disclosed in July 2020, continues to…
A critical path-traversal vulnerability (CVE-2025-64446) in Fortinet's FortiWeb web application firewall has been exploited by threat actors since early October 2025. This flaw allows unauthenticated attackers to create…
Fortinet has released security updates for critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO authentication. The vulnerabilities,…
Two significant vulnerabilities have been identified affecting various software versions. CVE-2025-64756 involves a command injection vulnerability in the glob CLI from versions 10.3.7 to 11.0.3. CVE-2025-64446 is a…
Fortinet's FortiWeb web application firewall has been compromised by two critical vulnerabilities, CVE-2025-64446 and CVE-2025-58034, both of which are under active exploitation. The first vulnerability allows…
Security researchers have identified a vulnerability in Cursor, an AI-powered code editor, that allows rogue Model Context Protocol (MCP) servers to inject malicious code into its internal browser. This exploit can…
More than 25,000 Fortinet devices with FortiCloud SSO enabled are exposed to remote attacks due to a critical authentication bypass vulnerability tracked as CVE-2025-59718. The U.S. has the highest number of affected…