Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryembedded-device-vulnerabilityperimeter-device-exposureactively-exploited-vulnerability

Multiple Critical Vulnerabilities Disclosed in Fortinet FortiSandbox and FortiWeb Products

Updated 3mo agoFirst seen Dec 17, 20256 sources

Fortinet has addressed several critical vulnerabilities affecting its FortiSandbox and FortiWeb products, with public advisories and technical details released on December 16, 2025. The most severe issues impact FortiSandbox, where multiple command injection vulnerabilities (CVE-2025-53949) allow authenticated attackers to execute arbitrary code as root via the admindel_confirm, name, and upload_vdi_file parameters. Additionally, a cross-site scripting vulnerability (CVE-2025-54353) in the hcproxy component could enable remote code execution with minimal user interaction. Fortinet has released patches for these flaws, and users are strongly advised to update affected systems immediately.

For FortiWeb, a critical authentication bypass vulnerability (CVE-2025-64447) was disclosed, stemming from improper verification of cryptographic signatures in the ApacheCookie_parse method, allowing unauthenticated attackers to gain access. These disclosures follow recent reports of active exploitation of a separate FortiWeb vulnerability (CVE-2025-64446), which enables unauthenticated attackers to create rogue administrator accounts and fully compromise exposed devices. Organizations using FortiWeb and FortiSandbox should review the official advisories and apply the recommended mitigations to prevent exploitation.

Share:
Multiple Critical Vulnerabilities Disclosed in Fortinet FortiSandbox and FortiWeb Products
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Dec 16, 20256mo ago

Technical details of FortiWeb exploit chain are publicly documented

By 2025-12-16, public reporting described how CVE-2025-64446 chained path traversal and authentication bypass issues to reach sensitive CGI scripts and impersonate administrators. Defenders were advised to look for suspicious POST requests, unexpected admin accounts, and anomalous logs.

CISA orders federal agencies to remediate exploited FortiWeb flaw

Following confirmation of active exploitation of CVE-2025-64446, CISA mandated remediation for U.S. federal agencies. The order reflected the risk posed by global scanning and exploitation campaigns targeting vulnerable FortiWeb devices.

Fortinet releases fixes and public advisories for FortiWeb and FortiSandbox flaws

On 2025-12-16, Fortinet released updates and coordinated public advisories covering FortiWeb vulnerabilities CVE-2025-64446 and CVE-2025-64447, as well as FortiSandbox vulnerabilities including CVE-2025-53949 and CVE-2025-54353. The advisories urged customers to apply patches immediately due to the severity of the issues.

Oct 10, 20259mo ago

FortiWeb auth bypass CVE-2025-64447 reported to Fortinet

Jason McFadyen of Trend Research reported the FortiWeb authentication bypass vulnerability CVE-2025-64447 to Fortinet on 2025-10-10. The issue involved improper verification of a cryptographic signature and could let remote attackers bypass authentication without user interaction.

Oct 1, 20259mo ago

Attackers begin exploiting FortiWeb CVE-2025-64446 in the wild

Active exploitation of FortiWeb path traversal vulnerability CVE-2025-64446 began in October 2025, according to reporting cited by watchTowr Labs and confirmed by Fortinet. The flaw allowed unauthenticated attackers to create rogue administrator accounts and take full control of affected devices.

May 1, 20251y ago

FortiSandbox RCE flaws reported to Fortinet

Jason McFadyen of Trend Research reported FortiSandbox command injection vulnerabilities later assigned CVE-2025-53949 to Fortinet in May 2025. The flaws affected multiple endpoints and could allow authenticated attackers to execute code as root.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Organizations
5 linked
FortinetTrend MicroCISAWatchTowrDefused Cyber
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.