Executive Summary
In June 2024, Fortinet disclosed a critical zero-day vulnerability in its FortiWeb web application firewall that was being actively exploited in the wild. Threat actors leveraged the unknown flaw to gain unauthorized access to targeted organizations, bypassing authentication and potentially altering application configurations or exfiltrating sensitive data. Fortinet responded promptly by releasing security patches and urging customers to update affected devices, while security researchers warned this campaign was already impacting several organizations before public disclosure.
This incident is part of a growing trend of sophisticated attacks targeting network and security appliances through undisclosed vulnerabilities. Organizations face heightened risk as attackers weaponize zero-days more quickly, making swift patch management and layered controls essential to defending digital infrastructure.
Why This Matters Now
This zero-day exploitation against a widely deployed security appliance underlines the urgent need for real-time vulnerability monitoring and proactive patching. With attackers rapidly leveraging zero-day exploits, delayed response can lead to widespread compromise, regulatory exposure, and disruption, especially as threat actors increasingly target core security infrastructure.
Attack Path Analysis
Attackers exploited a FortiWeb zero-day vulnerability to gain initial access to targeted cloud environments. Once inside, they likely attempted to escalate privileges by exploiting application misconfigurations or weak service accounts. The adversaries then moved laterally within the environment, targeting other workloads using east-west traffic flows. They established command and control through unauthorized outbound traffic, possibly leveraging covert channels. Data was exfiltrated via unmonitored egress pathways, bypassing basic detection. Finally, the attackers could disrupt operations or deploy ransomware to achieve their malicious objectives.
Kill Chain Progression
Initial Compromise
Description
Adversaries exploited a zero-day in FortiWeb to gain unauthorized access into the cloud application environment.
Related CVEs
CVE-2025-64446
CVSS 9.8A relative path traversal vulnerability in FortiWeb allows unauthenticated attackers to execute administrative commands via crafted HTTP(S) requests, potentially leading to full administrative control.
Affected Products:
Fortinet FortiWeb – 8.0.0 through 8.0.1, 7.6.0 through 7.6.4, 7.4.0 through 7.4.9, 7.2.0 through 7.2.11, 7.0.0 through 7.0.11
Exploit Status:
exploited in the wildCVE-2025-58034
CVSS 6.7An OS command injection vulnerability in FortiWeb allows authenticated attackers to execute arbitrary commands via crafted HTTP or CLI input, potentially leading to full system compromise.
Affected Products:
Fortinet FortiWeb – 8.0.0 through 8.0.1, 7.6.0 through 7.6.5, 7.4.0 through 7.4.10, 7.2.0 through 7.2.11, 7.0.0 through 7.0.11
Exploit Status:
exploited in the wildCVE-2025-25257
CVSS 9.6An SQL injection vulnerability in FortiWeb's Fabric Connector allows unauthenticated attackers to execute arbitrary SQL commands via crafted HTTP requests, leading to remote code execution.
Affected Products:
Fortinet FortiWeb – 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Exploitation for Client Execution
Exploitation for Privilege Escalation
Exploitation of Remote Services
Impair Defenses
Network Service Discovery
Data from Local System
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of Public-Facing Web Applications
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Regulation (EU) 2022/2554) – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Continuous Vulnerability Management
Control ID: Application and Workload Pillar: Protect
NIS2 Directive – Security of Network and Information Systems
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
FortiWeb zero-day exploitation threatens critical web application firewalls protecting banking platforms, payment systems, and customer data from advanced persistent threats.
Health Care / Life Sciences
Zero-day attacks on FortiWeb devices compromise patient data protection, HIPAA compliance, and medical application security in healthcare infrastructure environments.
Government Administration
Active exploitation of FortiWeb vulnerabilities exposes government web services, citizen data, and critical infrastructure to nation-state and criminal threat actors.
Information Technology/IT
IT service providers using FortiWeb face immediate risk from zero-day exploitation, affecting client security posture and managed service delivery capabilities.
Sources
- Fortinet warns of new FortiWeb zero-day exploited in attackshttps://www.bleepingcomputer.com/news/security/fortinet-warns-of-new-fortiweb-zero-day-exploited-in-attacks/Verified
- Alert: FortiWeb Zero-Day CVE-2025-64446 Actively Exploited – November 2025https://cyber.gov.rw/updates/article/alert-fortiweb-zero-day-cve-2025-64446-actively-exploited-november-2025/Verified
- Fortinet FortiWeb Zero-Day Exploited to Hijack Admin Accountshttps://cyberpress.org/fortinet-fortiweb-zero-day-exploited/Verified
- Fortinet admits it found another worrying zero-day being exploited in attackshttps://www.techradar.com/pro/security/fortinet-admits-it-found-another-worrying-zero-day-being-exploited-in-attacksVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive Zero Trust segmentation, granular east-west controls, egress policy enforcement, and real-time threat detection would have limited adversary movement, contained post-exploitation activities, and prevented or promptly detected exfiltration attempts in this cloud-native scenario.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Real-time inline inspection identifies and blocks known exploit signatures.
Control: Zero Trust Segmentation
Mitigation: Limits attacker reach by enforcing least-privilege access and application microsegmentation.
Control: East-West Traffic Security
Mitigation: Detects and blocks unauthorized internal traffic indicative of lateral movement.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks or alerts on suspicious outbound traffic destined for unauthorized endpoints.
Control: Cloud Firewall (ACF)
Mitigation: Identifies and blocks abnormal data transfers and cloud egress attempts.
Rapidly detects abnormal workload behaviors, enabling prompt containment.
Impact at a Glance
Affected Business Functions
- Web Application Security
- Network Security Management
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of sensitive configuration data and unauthorized access to protected web applications.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation and identity-based policies to prevent lateral attacker movement.
- • Implement comprehensive egress controls and URL filtering to block unauthorized outbound traffic and data theft.
- • Deploy inline threat detection and real-time anomaly response to swiftly identify exploitation attempts and suspicious behaviors.
- • Increase east-west traffic visibility, leveraging distributed enforcement and workload-centric controls.
- • Continuously monitor for new vulnerabilities and ensure rapid patching of exposed application surfaces.



