Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2025-25249

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

CVSS 8.1 heap overflow in FortiOS, FortiSwitchManager, and FortiSASE allows code execution via crafted packets. Actively exploited in PivotC2 RAT attacks; patched January 2026.

cat cve-2025-25249.json
Vendor
Fortinet
Product
FortiOS, FortiSwitchManager, FortiSASE
CVSS
8.1
EPSS (exploit probability)
0.8%
Status
kev
CISA patch-by (BOD 22-01)
Published

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets, per NVD. SecurityWeek characterizes the attack vector as unauthenticated.

Fortinet patched CVE-2025-25249 in January 2026. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 9, 2026, confirming active exploitation in the wild. Threat actors are using the vulnerability to deploy a remote access trojan called PivotC2, according to SecurityWeek.

Under CISA’s BOD 26-04, federal civilian agencies must apply mitigations by September 12, 2026. Check the NVD record above for specific fixed versions and the Fortinet PSIRT advisory linked there for upgrade guidance.