Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
CVSS 8.1 heap overflow in FortiOS, FortiSwitchManager, and FortiSASE allows code execution via crafted packets. Actively exploited in PivotC2 RAT attacks; patched January 2026.
- Vendor
- Fortinet
- Product
- FortiOS, FortiSwitchManager, FortiSASE
- CVSS
- 8.1
- EPSS (exploit probability)
- 0.8%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets, per NVD. SecurityWeek characterizes the attack vector as unauthenticated.
Fortinet patched CVE-2025-25249 in January 2026. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 9, 2026, confirming active exploitation in the wild. Threat actors are using the vulnerability to deploy a remote access trojan called PivotC2, according to SecurityWeek.
Under CISA’s BOD 26-04, federal civilian agencies must apply mitigations by September 12, 2026. Check the NVD record above for specific fixed versions and the Fortinet PSIRT advisory linked there for upgrade guidance.
