Back Securityweek Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports.
Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug was patched in January in FortiOS and FortiSwitchManager.
The flaw “may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests,” Fortinet noted in its advisory .
This week, SOCRadar warned that hackers have been exploiting the security defect to deploy the PivotC2 RAT on vulnerable devices.
A FortiGate post-exploitation tool, the backdoor provides attackers with interactive shell access, traffic tunneling, network scanning, and configuration harvesting capabilities.
SOCRadar believes that PivotC2 was likely developed with the use of AI and that threat actors have been using it in attacks since at least July 2026.
“The threat actors targeted more than 30,000 IP addresses, leading to the exploitation and infection of 178 devices with PivotC2,” SOCRadar says.
The attacks mainly targeted US entities, where at least two intrusions have resulted in data exfiltration.
According to the cybersecurity firm, the attacks are likely mounted by a Russian-speaking cybercrime actor.
On Wednesday, the US cybersecurity agency CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities ( KEV ) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04’s requirements.
Patches for the bug were rolled out in FortiOS versions 7.6.4, 7.4.9, 7.2.12, and 7.0.18, and in FortiSwitchManager versions 7.2.7 and 7.0.6. All organizations are advised to update to these or newer versions.
Related: Android’s September 2026 Updates Patch 180 Vulnerabilities
Related: Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories
Related: Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
Related: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
Android’s September 2026 Updates Patch 180 Vulnerabilities
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic.
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores.
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.
Exploit Published for Fresh Cleo Harmony Vulnerability
The security defect allows remote attackers to bypass authentication through argument bearer manipulation.
Chrome and Firefox Updates Patch Dozens of Vulnerabilities
The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
