CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks
CISA added actively exploited Fortinet CVE-2025-25249, a critical heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE, to its KEV catalog.
CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) allowing unauthorized code execution by sending specially crafted packets. CISA added it to the Known Exploited Vulnerabilities catalog on September 9, 2026, with a September 12 remediation deadline for federal agencies under BOD 26-04 and mandatory forensic triage of affected environments. Internet-facing Fortinet firewalls and SASE platforms are a likely foothold for credential theft, persistence, and lateral movement; ransomware use is currently listed as unknown.
- CVE-2025-25249 heap overflow enables code execution via crafted packets
- KEV addition Sept 9, 2026; federal patch deadline Sept 12 under BOD 26-04
- CISA requires forensic triage, not just routine patching
- Prioritize internet-exposed FortiOS, FortiSwitchManager, FortiSASE assets
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-25249 | Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known. Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product. | 9.8 | 2% | KEV PoC |
| mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants) |
Full article422 words · extracted from cybersecuritynews.com · click to collapse
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Fortinet vulnerability, tracked as CVE-2025-25249, to its Known Exploited Vulnerabilities catalog after confirming evidence of active exploitation.
The flaw affects FortiOS, FortiSwitchManager, and FortiSASE products. It could allow attackers to execute unauthorized code or commands by sending specially crafted packets.
CVE-2025-25249 is a heap-based buffer overflow vulnerability. A heap overflow occurs when an application writes more data into a memory area than it was designed to hold.
This can corrupt adjacent memory and potentially let an attacker alter program behavior, crash a device, or run malicious code with the privileges of the affected service. The issue is associated with CWE-122, heap-based buffer overflow, and CWE-787, out-of-bounds write.
Fortinet security appliances are commonly deployed at enterprise network boundaries, making FortiOS vulnerabilities especially significant.
A successful compromise of an internet-facing firewall, secure access service edge platform, or network-management tool could provide attackers with a foothold for further intrusion activity.
Fortinet Heap-based Buffer Overflow Flaw Exploited
Depending on the deployment, threat actors may attempt to steal credentials, change configurations, establish persistence, or move deeper into internal networks. CISA added the vulnerability to the KEV catalog on September 9, 2026, and set a remediation due date of September 12, 2026.
Federal civilian executive branch agencies must apply vendor-provided mitigations under Binding Operational Directive 26-04, which prioritizes security updates according to exploitation risk.
The agency also requires forensic triage for affected environments, indicating that organizations should investigate for possible compromise rather than treating the issue as a routine patching event.
CISA stated that organizations should follow Fortinet’s mitigation guidance and assess every affected asset for internet exposure. Where a cloud service is involved, stakeholders should follow applicable BOD 26-04 cloud-service guidance.
If no mitigation is available, CISA advises organizations to stop using the affected product. Security teams should identify all FortiOS, FortiSwitchManager, and FortiSASE deployments, prioritizing systems exposed to the public internet.
Administrators should apply the relevant Fortinet fixes or mitigations, review logs for suspicious traffic involving crafted packets, and check for unexpected configuration changes, administrative accounts, VPN activity, or outbound connections.
While CISA has confirmed exploitation, the agency currently lists ransomware use as unknown. Organizations should nevertheless treat the vulnerability as an active intrusion risk and conduct incident-response triage after remediation.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/fortinet-heap-based-buffer-overflow/