Cyber Security News

Critical Fortinet FortiWeb Vulnerability Exploited in the Wild to Create Admin Accounts

A critical vulnerability in Fortinet’s FortiWeb Web Application Firewall (WAF) is being actively exploited by threat actors, potentially as a zero-day attack vector.

The flaw, which enables unauthenticated attackers to gain administrator-level access to the FortiWeb Manager panel and WebSocket command-line interface, was first highlighted through a proof-of-concept (PoC) exploit shared by cyber deception firm Defused on October 6, 2025. This discovery came after Defused’s honeypot captured real-world attempts targeting exposed FortiWeb instances.​

FortiWeb serves as a vital defense mechanism, designed to detect and block malicious traffic aimed at web applications, making it a prime target for attackers seeking to undermine organizational security postures.

The vulnerability appears to stem from a path traversal issue that allows remote exploitation without prior access, potentially leading to full device compromise and subsequent lateral movement within networks.

Security firm Rapid7 confirmed the exploit’s efficacy through testing, noting it successfully creates unauthorized admin accounts like “hax0r” on vulnerable versions.​

The testing revealed significant differences in responses between the affected and patched versions.

On FortiWeb 8.0.1, released in August 2025, a successful exploit returns an HTTP 200 OK response with JSON details of the new admin user, including encrypted passwords and access profiles.

In contrast, version 8.0.2, released at the end of October, rejects the attempt with an HTTP 403 Forbidden error, indicating potential mitigation.

Rapid7 emphasized that while the public PoC fails against 8.0.2, it’s unclear if this update includes a deliberate silent fix or coincidental changes.​

Exploitation in the wild has been reported since October 2025, with Defused claiming targeted attacks on exposed devices. Global scanning and spraying of the exploit have escalated, involving IP addresses from regions like the US, Europe, and Asia.

Adding to the urgency, on November 6, 2025, Rapid7 spotted an alleged zero-day exploit for FortiWeb offered for sale on a prominent black hat forum, though its relation to this flaw remains unconfirmed.​

Hacker Forum claims

As of November 13, 2025, Fortinet has not issued official guidance, assigned a CVE identifier, or published a matching advisory on its PSIRT feed.

Organizations using FortiWeb versions before 8.0.2 face immediate risk and should prioritize emergency updates or isolate management interfaces from public exposure. Defenders are also urged to scan logs for suspicious admin account creations and monitor Fortinet’s channels for impending disclosures.​

The absence of vendor acknowledgment heightens concerns, especially given Fortinet’s history of targeted attacks.

Researchers at watchTowr Labs have even released tools to detect vulnerable instances by generating random admin users.

This incident underscores the need for rapid patching in critical infrastructure, as broad exploitation could soon follow initial targeted hits. Updates to this story will incorporate any official responses from Fortinet.​

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago