CISA_KEV · SEPTEMBER 2026 · EARLY WARNING

Fortinet Products Under Attack: CVE-2025-25249 Exploited

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
fortios (other)
Patched version
Not yet available
CVE-2025-25249

An early warning has been issued for a high-severity vulnerability in Fortinet FortiOS, FortiSwitchManager, and FortiSASE. The vulnerability, tracked as CVE-2025-25249, is reportedly being exploited in the wild.

What happened

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. The vulnerability, tracked as CVE-2025-25249, is under investigation and has been reportedly exploited in the wild. The exploit allows remote unauthenticated attackers to execute arbitrary code or commands, as noted in Fortinet's advisory.

The vulnerability was patched in January 2026, but threat actors have been observed exploiting it to deploy the PivotC2 RAT, according to SOCRadar. The flaw may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If fortios is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You may be affected if you are using Fortinet FortiOS, FortiSwitchManager, or FortiSASE. The exact version ranges are not yet published, so it is recommended to review all instances of these products and apply any available patches.

What should I do right now?

Contact Fortinet for patches and mitigations for the affected products. Review your network for any instances of FortiOS, FortiSwitchManager, and FortiSASE and apply any available patches immediately.

Has this been exploited in the wild?

Yes, the vulnerability is reportedly being exploited in the wild to deploy the PivotC2 RAT.

Sources

Join the 0Day waitlist →

← Back to all threats