A serious vulnerability affecting Fortinet FortiWeb has been exploited in recent days by cybercriminals, who create illegitimate administrator accounts without requiring any form of authentication. This weakness has raised alarm among organizations and security experts worldwide, as it allows full access to critical network infrastructure.

Fortinet has already integrated a fix into FortiWeb 8.0.2, urging administrators to immediately update their systems and check for possible unauthorized access.
First detections: A vulnerability already in use
Threat analysis firm Defused detected the first recorded exploit activity on October 6, when it observed an unknown exploit being used to create new administrator accounts on devices FortiWeb exposed
See also: CISA: Warns federal agencies about Cisco vulnerabilities
The attacks came from a wide range of IP addresses, including:
- 107.152.41.19
- 144.31.1.63
- Addresses within the range 185.192.70.0/24
- 64.95.13.8
The variety of sources indicates that the exploit is now widely distributed, perhaps through automated scanning tools.
Confirmation from watchTowr Labs: Connection attempt – exploit – access
Security analysts at watchTowr Labs published a video demonstrating the problem: a failed login attempt to FortiWeb is followed by the execution of the exploit, which in turn allows successful login as a new administrator.
Additionally, the team released a tool called “FortiWeb Authentication Bypass Artifact Generator”which can help organizations and analysts identify whether a system is exposed.
Which versions are affected – Where is the vulnerability located?
According to Rapid7, the issue is found in FortiWeb versions 8.0.1 and earlier, with version 8.0.2 resolving the issue. Despite the severity of the vulnerability, there is still no report on Fortinet's PSIRT site, raising questions about the official notification process.
See also: Vulnerability in Dell Data Lakehouse allows privilege escalation

The vulnerability is related to an incorrect path that allows attackers to execute requests to the following endpoint:
/api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi
Through POST requests, attackers can create new accounts administrator, completely bypassing the authentication mechanism.
How attackers operate – Examples of malicious accounts
According to the findings of Daniel Card (PwnDefend / Defused), attackers create multiple accounts with usernames such as:
- Testpoint
- trader1
- trader
The passwords that have been identified are equally characteristic:
- 3eMIXX43
- AFT3$tH4ck
- AFT3$tH4ckmet0d4yaga!n
Creating multiple admin accounts suggests an automated process and an attempt to maintain access even if an account is discovered and removed.
The situation is escalating: Global spread of attacks
Since the initial reports in early October, the attacks have not only continued but have expanded internationally. Many organizations that expose FortiWeb appliances directly to the internet are reporting suspicious activity.
The absence of official documentation from Fortinet is adding to the climate of concern, with several experts calling for a more transparent notification process.
See also: CISA: WatchGuard Fireware flaw exposes 54,000 Fireboxes

What administrators should do immediately
Given the seriousness of the situation, experts recommend specific steps:
1. Immediate update to FortiWeb 8.0.2 or later
It is the only confirmed fix for now.
2. Check for unrecognized admin accounts
Especially those that have been created recently.
3. Review logs for requests to the “fwbcgi”
Any activity there is an indication of an attack.
4. Access restriction
Management interfaces should only via VPN or from trusted networks. Direct exposure to the internet is a high risk.
Another reminder of the importance of patching
This incident highlights once again how vulnerable network devices can be when left unpatched. With attackers already exploiting the security gap, administrators must act quickly and decisively – before the vulnerability leads to serious breaches of infrastructure and data.
Source: www.bleepingcomputer.com
