CVE-2025-64446
CISA KEVAs of 2026-02-26, CVE-2025-64446 is a CVSS 9.4 (CRITICAL-severity) vulnerability. CISA KEV-listed (known exploited); Public exploit code available; Nuclei detection template exists. EPSS exploitation probability 89.5%. Threadlinqs Intelligence tracks 3 threats exploiting it.
Last updated: 2026-02-26
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
Weaknesses (CWE)
CWE-23
Exploitation status
CISA KEV-listed (known exploited) · public exploit code available · nuclei detection template exists
- sensepost/CVE-2025-64446 (github)
- lincemorado97/CVE-2025-64446_CVE-2025-58034 (github)
- sxyrxyy/CVE-2025-64446-FortiWeb-CGI-Bypass-PoC (github)
- soltanali0/CVE-2025-64446-Exploit (github)
- fevar54/CVE-2025-64446-PoC---FortiWeb-Path-Traversal (github)
- verylazytech/CVE-2025-64446 (github)
- AN5I/cve-2025-64446-fortiweb-exploit (github)
- D3crypT0r/CVE-2025-64446 (github)
Threats tracking this CVE
- ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2 — HIGH
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers — HIGH
- ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchers — HIGH
References
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.