Active Exploitation of FortiGate Vulnerability with Node.js Malware
Article Content
Threat actors are actively exploiting CVE-2025-25249, a critical heap-based buffer overflow vulnerability in FortiGate firewalls, to deploy a custom Node.js malware framework called PivotC2. This framework allows attackers to turn compromised devices into long-term footholds for espionage and data theft. Despite Fortinet's patch release in January 2026, SOCRadar's Threat Research Unit has confirmed ongoing exploitation with high confidence. The vulnerability affects FortiOS, FortiSwitchManager, and certain FortiSASE releases, enabling unauthenticated remote code execution via specially crafted packets. The compromised firewalls can be used to monitor traffic, collect credentials, and maintain persistence within corporate networks. Organizations using affected versions must assess whether their systems have been compromised before applying the patch. The situation highlights the rapid evolution from a patch management issue to a critical post-exploitation threat.
Key Points: • CVE-2025-25249 is being actively exploited in the wild. • Attackers deploy the Node.js-based PivotC2 malware on compromised FortiGate devices. • Fortinet released a patch in January 2026, but exploitation continues.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.