Critical Buffer Overflow Vulnerability in Fortinet Devices

Critical Buffer Overflow Vulnerability in Fortinet Devices

First seen 9 Sep 2026, 23:43 UTC RedpacketsecurityButtondownexploitbulletin.comwww.vulncheck.com 76.7

Article Content

Browse articles
ThreatCluster

A heap-based buffer overflow vulnerability (CVE-2025-25249) has been identified in Fortinet's FortiOS and FortiSwitchManager, allowing unauthenticated code execution via specially crafted packets. This affects multiple versions of FortiOS (7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17, and 6.4) and FortiSwitchManager (7.2.0–7.2.6, 7.0.0–7.0.5). The vulnerability was added to the VulnCheck known-exploited catalog on September 8, 2026, following reports of a purpose-built RAT (PivotC2) being deployed on unpatched devices. Organizations using these affected systems are urged to apply emergency updates immediately due to the active exploitation of this vulnerability. The risk is particularly high for devices exposed to the internet, as attackers can execute unauthorized commands without authentication. The current status is critical, with CISA adding it to the KEV catalog on September 9, 2026.

Key Points: • CVE-2025-25249 allows unauthenticated code execution on Fortinet devices. • Active exploitation reported with a RAT being deployed on unpatched systems. • Immediate patching is required for affected FortiOS and FortiSwitchManager versions.

Ask AI about this cluster

Timeline

2026-01-13
CVE-2025-25249 published
Fortinet disclosed a heap-based buffer overflow vulnerability affecting multiple versions of FortiOS and FortiSwitchManager.
Buttondown
2026-09-08
Vulnerability added to known-exploited catalog
CVE-2025-25249 was added to VulnCheck's known-exploited catalog following reports of exploitation.
Buttondown
2026-09-09
CISA adds CVE to KEV catalog
CISA officially listed CVE-2025-25249 in the KEV catalog, indicating active exploitation.
Buttondown