Story perspectives
Fortinet Faces Backlash Over Critical Security Flaw Exploited Early
11/19/2025
1 of 1
Story summary
- Security researchers report that CVE-2025-64446 affects Fortinet's FortiWeb appliances, including a path traversal and an authentication bypass, and has been exploited since early October 2025, ahead of November 14, 2025 advisory.
- The vulnerabilities allow unauthorized access to internal systems and administrative impersonation.
- Fortinet issued silent patches and faces criticism for delayed disclosure, with experts arguing it could have endangered customers.
- Fortinet recommends disabling HTTP/HTTPS on exposed interfaces until upgrades finish.
