Active Exploitation of FortiGate Vulnerability with Node.js Malware

Active Exploitation of FortiGate Vulnerability with Node.js Malware

First seen 9 Sep 2026, 13:13 UTC CybersecuritynewsLinkedin 72.6

Article Content

Browse articles
ThreatCluster

Threat actors are actively exploiting CVE-2025-25249, a critical heap-based buffer overflow vulnerability in FortiGate firewalls, to deploy a custom Node.js malware framework called PivotC2. This framework allows attackers to turn compromised devices into long-term footholds for espionage and data theft. Despite Fortinet's patch release in January 2026, SOCRadar's Threat Research Unit has confirmed ongoing exploitation with high confidence. The vulnerability affects FortiOS, FortiSwitchManager, and certain FortiSASE releases, enabling unauthenticated remote code execution via specially crafted packets. The compromised firewalls can be used to monitor traffic, collect credentials, and maintain persistence within corporate networks. Organizations using affected versions must assess whether their systems have been compromised before applying the patch. The situation highlights the rapid evolution from a patch management issue to a critical post-exploitation threat.

Key Points: • CVE-2025-25249 is being actively exploited in the wild. • Attackers deploy the Node.js-based PivotC2 malware on compromised FortiGate devices. • Fortinet released a patch in January 2026, but exploitation continues.

Ask AI about this cluster

Timeline

2026-01-13
CVE-2025-25249 published
Fortinet disclosed a critical heap-based buffer overflow vulnerability affecting FortiOS and related products.
Linkedin
2026-09-08
Active exploitation confirmed
SOCRadar reported high confidence in active exploitation of FortiGate firewalls using CVE-2025-25249.
Cybersecuritynews
2026-09-09
Current exploitation status
Threat actors are using the PivotC2 framework to maintain footholds in compromised networks.
Linkedin