FortiWeb WAF — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 15, 2025
Last Seen
August 13, 2026

Related Threat Clusters

  • FortiWeb WAF Vulnerability Enables Full Admin Control Exploitation

    A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…

    100 articles · Updated November 15, 2025
  • FortiWeb WAF Vulnerability Exploited for Full Admin Control

    A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access. Organizations using FortiWeb WAF are at risk of total control being…

    2 articles · Updated November 15, 2025
  • Critical RCE Vulnerabilities Discovered in Fortinet Products

    Fortinet has identified multiple critical vulnerabilities in its FortiSandbox and FortiAuthenticator products, which could allow unauthenticated attackers to execute arbitrary code remotely. The vulnerabilities are…

    98 articles · Updated May 12, 2026
  • Multiple Vulnerabilities Discovered in Fortinet Products

    Two vulnerabilities have been identified in Fortinet products affecting FortiOS and FortiWeb. The first, a stack-based buffer overflow in FortiOS explicit proxy, allows unauthenticated attackers to execute arbitrary…

    2 articles · Updated August 13, 2026
  • Critical Vulnerabilities in Fortinet FortiWeb Actively Exploited

    Fortinet's FortiWeb web application firewall has been compromised by two critical vulnerabilities, CVE-2025-64446 and CVE-2025-58034, both of which are under active exploitation. The first vulnerability allows…

    74 articles · Updated November 28, 2025
  • CISA Reports Exploitation of FortiWeb WAF Vulnerability for Admin Access

    CISA has reported active attacks exploiting a vulnerability in Fortinet's FortiWeb Web Application Firewall (WAF) that allows unauthorized admin access. Organizations using FortiWeb are at risk, and immediate action is…

    2 articles · Updated November 18, 2025
  • Code Formatters Expose Sensitive Credentials from Major Organizations

    Thousands of credentials, authentication keys, and configuration data from banks, government, and tech organizations were found in publicly accessible JSON snippets submitted to the JSONFormatter and CodeBeautify tools.…

    4 articles · Updated November 25, 2025
  • Code Formatting Tools Expose Sensitive Credentials

    Researchers from watchTowr discovered that over 80,000 sensitive credentials, including authentication keys and API tokens, were exposed through JSON snippets submitted to the JSONFormatter and CodeBeautify tools. This…

    4 articles · Updated November 25, 2025

Recent Intelligence Reports

  • FG IR 26 157 — fortiguard.fortinet.com · August 13, 2026
  • Developers left large cache of credentials exposed on code generation websites — Csoonline · November 25, 2025
  • CISA Reports Active Attacks on FortiWeb WAF Vulnerability Allowing Admin Access — Gbhackers · November 18, 2025
  • Critical FortiWeb WAF Flaw Actively Exploited to Establish Admin Access and Seize Total Control — Gbhackers · November 15, 2025
  • Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover — Cybersecuritynews · November 15, 2025

CVSS v3.1 Breakdown