Elena Nikulina

Qualys: Fortinet FortiWeb vulnerability exploited, CISA updates KEV list

Qualys: Fortinet FortiWeb vulnerability exploited, CISA updates KEV list
@qualys: Qualys alerts on Fortinet flaw

A critical vulnerability in Fortinet FortiWeb (CVE-2025-64446) is under active exploitation.

According to Qualys, this security flaw allows attackers to bypass authentication controls and potentially gain control of vulnerable devices. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has responded by adding this vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, setting a mitigation deadline of November 21. Experts urge organizations using affected versions of FortiWeb to take immediate action to secure their systems.

Furthermore, the vulnerability highlights the ongoing cybersecurity challenges faced by businesses, emphasizing the importance of regular updates and vigilance in network security management. Qualys provides detailed information on the exploit, affected devices, and recommended mitigation steps, accessible through their official website.

The heightened urgency around FortiWeb underscores persistent risks in cloud environments, reminiscent of prior incidents where Qualys revealed the implications of an AWS misconfiguration exposing 70 TB of data. These developments further highlight the value of proactive cybersecurity education, echoing Qualys's commitment to advancing industry knowledge through initiatives such as their cybersecurity insights shared with students at the Pune office.

This material may contain third-party opinions, none of the data and information on this webpage constitutes investment advice according to our Disclaimer. While we adhere to strict Editorial Integrity, this post may contain references to products from our partners.
Weekly Top Bonuses
up to $2,500
deposit bonus for all clients
CLAIM BONUS
Your capital is at risk.