Target Industry

The target industries for Fortinet FortiWeb are organisations that rely heavily on web applications and APIs for critical operations. 

Overview

A critical path traversal vulnerability in Fortinet FortiWeb has been actively exploited in the wild since early October 2025. The flaw enables unauthenticated attackers to create new administrative accounts, granting full control over the device. A public proof-of-concept (PoC) exploit is circulating, significantly increasing the likelihood of widespread compromise. The issue appears to have been silently patched in FortiWeb version 8.0.2, but no official CVE or advisory has been published by Fortinet at the time of writing. 

Impact

Exploiting this vulnerability gives attackers full administrative control of FortiWeb, enabling them to disable protections, alter configurations, and create backdoors. This compromises web application security, heightens data breach risk, and exposes organisations to GDPR penalties. It can also cause operational disruption, facilitate lateral movement for ransomware, and damage reputation through public disclosure. 

Affected Products

FortiWeb versions 8.0.1 and earlier are confirmed vulnerable, while exploit attempts against version 8.0.2 fail and management interfaces exposed to the internet remain at highest risk. 

Exploitation

The Fortinet FortiWeb flaw is exploited via a path traversal vulnerability that lets attackers bypass authentication and create admin accounts. By sending crafted HTTP POST requests to a vulnerable endpoint, threat actors can add local admin users such as ‘Testpoint’ or ‘trader1’ with preset passwords. No prior authentication is required, and exploitation works on versions 8.0.1 and earlier, while version 8.0.2 appears patched. A public PoC and tools like the FortiWeb Authentication Bypass Artifact Generator make exploitation trivial. 

Containment, Mitigations & Remediations

Organisations should immediately upgrade to FortiWeb version 8.0.2 or later, as earlier versions remain vulnerable. Remove management interfaces from public internet access and restrict them to trusted networks or VPN. Enforce strong access controls, monitor for unauthorised admin accounts and suspicious POST requests, and apply temporary WAF or firewall rules to block the vulnerable endpoint if patching is delayed. 

Threat Landscape

The flaw is being weaponised amid a surge in automated reconnaissance and exploitation. Cybercriminals increasingly leverage AI and commoditised exploit kits, accelerating attack speed and scale. Public PoC availability and underground forum chatter about a zero-day exploit for sale indicate strong interest from threat actors. 

Threat Group

The identity of the threat actor remains unknown, but evidence points to opportunistic campaigns rather than targeted attacks. Activity suggests indiscriminate exploitation for persistence and lateral movement, with links to underground forums selling FortiWeb exploits. This indicates involvement of Cybercrime-as-a-Service ecosystems rather than a single advanced persistent threat (APT). 

Further Information

https://thehackernews.com/2025/11/fortinet-fortiweb-flaw-actively.html

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content