Fortinet Flaw CVE-2025-25249 Used in PivotC2 RAT Attacks
CVSS 8.1 heap overflow in FortiOS is exploited with PivotC2 RAT. January 2026 patch available; CISA BOD 26-04 deadline for federal agencies is September 12.

Threat actors are exploiting a heap buffer overflow in Fortinet network products to deploy a remote access trojan called PivotC2, SecurityWeek reported Wednesday. The fix has been available since January 2026. CISA confirmed active exploitation by adding CVE-2025-25249 to its Known Exploited Vulnerabilities catalog on September 9.
What’s affected
CVE-2025-25249 is a heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE. An attacker can send specially crafted packets to trigger unauthorized code execution, per NVD. SecurityWeek describes the attack vector as unauthenticated, which puts any internet-accessible Fortinet device on a vulnerable build directly in range. CVSS score: 8.1 (high).
What PivotC2 is
PivotC2 is the remote access trojan documented in these attacks. Technical details beyond what SecurityWeek has published are limited at this stage. What is confirmed: attackers are reaching post-exploitation access on unpatched Fortinet gear. The RAT’s persistence mechanism and command infrastructure have not yet been publicly detailed.
Nine months, same problem
The patch shipped in January 2026. Active exploitation is documented in September 2026. That gap is not unusual for Fortinet hardware.
Network security appliances in data centers, OT environments, and managed service provider stacks need maintenance windows, change-control approval, and sometimes vendor coordination before firmware goes in. The result is the same pattern repeated: FortiOS CVE-2025-68686 hit the KEV catalog in July, months after its fix shipped. FortiSandbox saw two 9.8-rated unauth RCEs added to KEV that same month. FortiWeb and FortiManager followed in August.
If Fortinet appliances in your environment have internet exposure, treat each PSIRT bulletin as a patch-now task rather than a patch-next-cycle task. The window between “fix available” and “actively exploited” keeps closing.
What to do
Fortinet released fixed builds in January 2026. Check the NVD record for CVE-2025-25249 for specific fixed versions of FortiOS, FortiSwitchManager, and FortiSASE, and follow the linked Fortinet PSIRT advisory for upgrade paths.
Federal civilian agencies are under CISA’s BOD 26-04 deadline of September 12, 2026. If you’re in federal scope and haven’t patched, this is the only open item that matters right now.
For everyone else: FortiOS and FortiSwitchManager with any internet exposure should be patched this week. FortiSASE deployments should be confirmed against the advisory regardless of exposure profile, since cloud-managed services sometimes lag behind what the vendor has already updated in other configurations.
- [ HIGH ]CVE-2025-25249Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Found this useful? Share it.


