Fortinet FortiWeb path traversal flaw, actively exploited
Vulnerability
Summary
Hide ▲
Show ▼
Fortinet FortiWeb path traversal is being actively exploited to create new admin users on exposed devices without authentication, creating immediate takeover risk for internet-facing systems. The flaw affects FortiWeb 8.0.1 and earlier and is fixed in 8.0.2. Administrators should treat exposed management interfaces as at risk and verify whether unauthorized accounts or suspicious requests are present.
Related Happenings
FortiClient EMS improper access control flaw (CVE-2026-35616)
Vulnerability
H score59
First: 05.04.2026 21:45
Last: 05.04.2026 21:45
Sources 1
About this happening:
CVE-2026-35616 is an actively exploited improper access control flaw in FortiClient Enterprise Management Server (EMS) that lets unauthenticated attackers execute code...
FortiClient EMS improper access control flaw (CVE-2026-35616)
VulnerabilityAbout this happening: CVE-2026-35616 is an actively exploited improper access control flaw in FortiClient Enterprise Management Server (EMS) that lets unauthenticated attackers execute code...
Latest development: 28.05.2026 18:26
Attackers were already abusing CVE-2026-35616 against FortiClient EMS in May 2026. The flaw provided pre-auth API access bypass and privilege escalation before remediation in 7.4.7 and later.
Fortinet FortiClient EMS SQL injection actively exploited SQL injection flaw (CVE-2026-21643)
Vulnerability
H score51
First: 30.03.2026 10:48
Last: 30.03.2026 10:48
Sources 1
About this happening:
Active exploitation of CVE-2026-21643 is putting Fortinet FortiClient EMS deployments at risk of unauthenticated arbitrary code or command execution on unpatched syste...
Fortinet FortiClient EMS SQL injection actively exploited SQL injection flaw (CVE-2026-21643)
VulnerabilityAbout this happening: Active exploitation of CVE-2026-21643 is putting Fortinet FortiClient EMS deployments at risk of unauthenticated arbitrary code or command execution on unpatched syste...
FortiOS SSO authentication bypass (CVE-2026-24858)
Vulnerability
H score51
First: 28.01.2026 06:49
Last: 28.01.2026 06:49
Sources 1
About this happening:
CVE-2026-24858 is a critical FortiOS authentication bypass affecting FortiOS, FortiManager, and FortiAnalyzer, and it is being actively exploited in the wild...
FortiOS SSO authentication bypass (CVE-2026-24858)
VulnerabilityAbout this happening: CVE-2026-24858 is a critical FortiOS authentication bypass affecting FortiOS, FortiManager, and FortiAnalyzer, and it is being actively exploited in the wild...
Latest development: 10.03.2026 18:21
SentinelOne said attackers are abusing FortiGate NGFW appliances through known vulnerabilities and weak credentials, including CVE-2026-24858, to steal configuration files and service account credentials from healthcare, government, and managed service provider environments.
Fortinet FortiCloud SSO mitigation guidance
Advisory/Mitigation
H score51
First: 28.01.2026 01:19
Last: 28.01.2026 01:19
Sources 1
About this happening:
Fortinet advised customers to restrict administrative access and disable FortiCloud SSO to reduce abuse of an actively exploited authentication bypass affecting de...
Fortinet FortiCloud SSO mitigation guidance
Advisory/MitigationAbout this happening: Fortinet advised customers to restrict administrative access and disable FortiCloud SSO to reduce abuse of an actively exploited authentication bypass affecting de...
Fortinet CVE-2025-59718 mitigation guidance
Advisory/Mitigation
H score56
First: 23.01.2026 12:39
Last: 23.01.2026 12:39
Sources 1
About this happening:
Fortinet told customers to immediately harden FortiCloud SSO exposure for CVE-2025-59718, because attackers are still abusing the flaw against fully patched firewall...
Fortinet CVE-2025-59718 mitigation guidance
Advisory/MitigationAbout this happening: Fortinet told customers to immediately harden FortiCloud SSO exposure for CVE-2025-59718, because attackers are still abusing the flaw against fully patched firewall...
Timeline
-
14.11.2025 04:41 1 articles · 8mo ago
FortiWeb path traversal abuse first spotted on exposed devices
Exploitation ObservedDefused identified an unknown Fortinet exploit on exposed FortiWeb devices on October 6, with attackers using the path traversal flaw to create admin accounts without authentication.
Show sources
- Fortinet FortiWeb flaw with public PoC exploited to create admin users — www.bleepingcomputer.com — 14.11.2025 04:41
-
14.11.2025 04:41 2 articles · 8mo ago
Researchers confirm FortiWeb path traversal flaw and 8.0.2 fix
Technical Analysis UpdateResearchers from PwnDefend, Defused, watchTowr Labs, and Rapid7 confirmed that FortiWeb 8.0.1 and earlier are affected by a path traversal flaw at /api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi, where HTTP POST requests can create local admin-level accounts; the issue is fixed in FortiWeb 8.0.2, and defenders are advised to review logs, unusual administrative accounts, and access from suspicious IPs.
Show sources
- Fortinet FortiWeb flaw with public PoC exploited to create admin users — www.bleepingcomputer.com — 14.11.2025 04:41
- Fortinet FortiWeb flaw with public PoC exploited to create admin users — www.bleepingcomputer.com — 14.11.2025 04:41