Fortinet Products Under Attack: CVE-2025-25249 Exploited
- Severity
- HIGH
- Affected component
- fortios (other)
- Patched version
- Not yet available
An early warning has been issued for a high-severity vulnerability in Fortinet FortiOS, FortiSwitchManager, and FortiSASE. The vulnerability, tracked as CVE-2025-25249, is reportedly being exploited in the wild.
What happened
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. The vulnerability, tracked as CVE-2025-25249, is under investigation and has been reportedly exploited in the wild. The exploit allows remote unauthenticated attackers to execute arbitrary code or commands, as noted in Fortinet's advisory.
The vulnerability was patched in January 2026, but threat actors have been observed exploiting it to deploy the PivotC2 RAT, according to SOCRadar. The flaw may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
What to do about it
- Contact Fortinet for patches and mitigations for FortiOS, FortiSwitchManager, and FortiSASE.
- Review your network for any instances of FortiOS, FortiSwitchManager, and FortiSASE and apply any available patches immediately.
- Monitor network traffic for any signs of unauthorized code execution or unusual activity.
- No official fix has been published yet for the affected components. Monitor the sources below for updates.
How 0Day would have caught this
fortios is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using Fortinet FortiOS, FortiSwitchManager, or FortiSASE. The exact version ranges are not yet published, so it is recommended to review all instances of these products and apply any available patches.
What should I do right now?
Contact Fortinet for patches and mitigations for the affected products. Review your network for any instances of FortiOS, FortiSwitchManager, and FortiSASE and apply any available patches immediately.
Has this been exploited in the wild?
Yes, the vulnerability is reportedly being exploited in the wild to deploy the PivotC2 RAT.