Target Industry
The target industries for Fortinet FortiWeb are organisations that rely heavily on web applications and APIs for critical operations.
Overview
A critical path traversal vulnerability in Fortinet FortiWeb has been actively exploited in the wild since early October 2025. The flaw enables unauthenticated attackers to create new administrative accounts, granting full control over the device. A public proof-of-concept (PoC) exploit is circulating, significantly increasing the likelihood of widespread compromise. The issue appears to have been silently patched in FortiWeb version 8.0.2, but no official CVE or advisory has been published by Fortinet at the time of writing.
Impact
Exploiting this vulnerability gives attackers full administrative control of FortiWeb, enabling them to disable protections, alter configurations, and create backdoors. This compromises web application security, heightens data breach risk, and exposes organisations to GDPR penalties. It can also cause operational disruption, facilitate lateral movement for ransomware, and damage reputation through public disclosure.
Affected Products
FortiWeb versions 8.0.1 and earlier are confirmed vulnerable, while exploit attempts against version 8.0.2 fail and management interfaces exposed to the internet remain at highest risk.
Exploitation
The Fortinet FortiWeb flaw is exploited via a path traversal vulnerability that lets attackers bypass authentication and create admin accounts. By sending crafted HTTP POST requests to a vulnerable endpoint, threat actors can add local admin users such as ‘Testpoint’ or ‘trader1’ with preset passwords. No prior authentication is required, and exploitation works on versions 8.0.1 and earlier, while version 8.0.2 appears patched. A public PoC and tools like the FortiWeb Authentication Bypass Artifact Generator make exploitation trivial.
Containment, Mitigations & Remediations
Organisations should immediately upgrade to FortiWeb version 8.0.2 or later, as earlier versions remain vulnerable. Remove management interfaces from public internet access and restrict them to trusted networks or VPN. Enforce strong access controls, monitor for unauthorised admin accounts and suspicious POST requests, and apply temporary WAF or firewall rules to block the vulnerable endpoint if patching is delayed.
Threat Landscape
The flaw is being weaponised amid a surge in automated reconnaissance and exploitation. Cybercriminals increasingly leverage AI and commoditised exploit kits, accelerating attack speed and scale. Public PoC availability and underground forum chatter about a zero-day exploit for sale indicate strong interest from threat actors.
Threat Group
The identity of the threat actor remains unknown, but evidence points to opportunistic campaigns rather than targeted attacks. Activity suggests indiscriminate exploitation for persistence and lateral movement, with links to underground forums selling FortiWeb exploits. This indicates involvement of Cybercrime-as-a-Service ecosystems rather than a single advanced persistent threat (APT).
Further Information
https://thehackernews.com/2025/11/fortinet-fortiweb-flaw-actively.html
Intelligence Terminology Yardstick












