Wednesday , September 9 2026
FortiWeb

FortiWeb Auth Bypass Vuln Exploited: Script to Detect Vuln Appliances

A Fortinet FortiWeb vulnerability is being exploited to create new admin users on exposed devices without any authentication. The issue is fixed in FortiWeb 8.0.2, and admins are urged to update as soon as possible and check for signs of unauthorized access.

Source: Defused

Threat intelligence firm Defused discovered an “Unknown Fortinet exploit” targeting exposed devices to create admin accounts on October 6.

FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
FortiSandbox, FortiOS, FortiProxy ZTNA flaws unveil, while Fortigate firewall actively exploited

Microsoft Patch Tuesday September 2026 Fixed 973 Flaws Fixed, 2 Zero-Days

Microsoft shared its September 2026 security updates on September 8. These updates fix 973 flaws, including two serious issues that...
Read More
Microsoft Patch Tuesday September 2026  Fixed 973 Flaws Fixed, 2 Zero-Days

A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

A single phone call caused one of the biggest data breaches in Dutch history. In early February 2026, the big...
Read More
A single call: ShinyHunters Gained Access to 6 Million Customers’ Records

The first zero-click worm to spread through WeChat calls across iOS and Android

A worm called “WeWorm” can spread through WeChat voice calls on iOS and Android. It takes over a target's WeChat...
Read More
The first zero-click worm to spread through WeChat calls across iOS and Android

USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

Bimbo Bakeries USA has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle’s E-Business Suite (EBS). In...
Read More
USA Bimbo Bakeries Confirms Data Stolen in Oracle EBS Zero-Day Attack

ALERT
Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

Roundcube Webmail has given security updates for its 1.6 LTS and 1.7 branches. These updates fix 12 problems that could...
Read More
ALERT  Roundcube Webmail fixes 12 security flaws, including zero-click XSS and SSRF bypass

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used a small Windows backdoor called...
Read More
New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

Attackers are misusing MikroTik routers through their Secure Shell (SSH) service, which can be accessed from the internet, to take...
Read More
Hackers Exploiting MikroTik RouterOS Flaw Gaining Network Access

CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

CrowdStrike launched CrowdStrike SafeMind, a set of special security models and tools from the CrowdStrike Cyber Superintelligence Lab. The SafeMind...
Read More
CrowdStrike launches SafeMind, the first agentic cybersecurity solution for defenders

Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

Chinese-speaking hackers have added Claude, Qwen, and DeepSeek to their hacking system to automate cyberattacks on governments and other targets...
Read More
Claude, DeepSeek, and Qwen AI agents combinedly used to hit gov.t across Asia

According to new research published by Daniel Card of PwnDefend and Defused, the flaw is a path traversal issue affecting the following Fortinet endpoint: (/api/v2.0/cmdb/system/admin%3f/../../../../../cgi-bin/fwbcgi)

Threat actors are sending HTTP POST requests to this path containing payloads that create local admin-level accounts on the targeted device.

Researchers found multiple sets of usernames and passwords like Testpoint, trader1, and trader, with passwords including 3eMIXX43, AFT3$tH4ck, and AFT3$tH4ckmet0d4yaga!n.

The attacks originated from a wide range of IP addresses, including:

107.152.41.19
144.31.1.63
Addresses in the 185.192.70.0/24 range
64.95.13.8 (from original October report)

Security researchers at watchTowr Labs have verified the exploit, sharing a video on X that shows a failed FortiWeb login attempt, the exploit execution, and the successful login as the new admin user.

watchTowr also released a tool called “FortiWeb Authentication Bypass Artifact Generator,” which attempts to exploit the flaw by creating an admin user with an 8-character random username derived from a UUID.

The tool was released to help defenders identify vulnerable devices.

Rapid7 reports that the flaw impacts FortiWeb versions 8.0.1 and earlier. It was resolved in version 8.0.2, released at the end of October.

BleepingComputer reported an inability to find any disclosure of a FortiWeb vulnerability on Fortinet’s PSIRT site that matches the one being exploited.

WatchTowr Labs’ open-source tool, hosted on GitHub at watchTowr-vs-Fortiweb-AuthBypass, simplifies detection by simulating the bypass mechanism. The Python script generates a unique username and password (e.g., “35f36895”) and sends an exploit payload to the target IP, such as python watchTowr-vs-Fortiweb-AuthBypass.py 192.168.1.99.

Source: Defused, pwndefend, Daniel_Card, BleepingComputer

Check Also

Anthropic

Anthropic’s Claude Code Source Code Reportedly Leaked

Anthropic’s special Claude Code CLI tool had its complete TypeScript source code inadvertently exposed due …