
CVE-2025-64446: Critical Fortinet FortiWeb Path Traversal Vulnerability Exploited to Create Administrative Accounts
On 13 November 2025, open source reporting?began detailing active exploitation of a silently patched Fortinet?FortiWeb?vulnerability. The flaw is a path traversal issue in the?FortiWeb?web application?firewall?(WAF)








