ZeroHour
Canadian Centre for Cyber Securitypublished ()ingested Canadian Centre for Cyber Security
Part of a story covered by 4 sources: “Fortinet CVE-2025-25249 Exploited to Deploy PivotC2 RAT; CISA Adds Flaw to KEV Catalog” — merged summary and timeline →

Fortinet security advisory (AV26-023) - Update 1

highExploit / PoC exploited in the wildimportance 60CVE-2025-25249CVE-2025-47855CVE-2025-64155
AI summary · glm-5.3-flash

CISA added Fortinet CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its KEV catalog; Canadian Cyber Centre urges patching.

The Canadian Centre for Cyber Security updated advisory AV26-023, which relays January 2026 Fortinet advisories covering FortiFone, FortiOS, FortiSASE, FortiSIEM, and FortiSwitchManager. On September 9, 2026, CISA added CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its Known Exploited Vulnerabilities catalog. Related Fortinet flaws include unauthenticated local configuration access (CVE-2025-47855) and unauthenticated remote command injection (CVE-2025-64155). Administrators should review the advisories and apply available updates.

  • CVE-2025-25249 (heap overflow in cw_acd daemon) added to CISA KEV on September 9, 2026.
  • CVE-2025-47855 allows unauthenticated local configuration access; CVE-2025-64155 enables remote command injection.
  • Affected products span FortiFone, FortiOS, FortiSASE, FortiSIEM, and FortiSwitchManager.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25249
Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known.

Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product.

9.82% KEV PoC
  • Fortinet FortiOS
  • Fortinet FortiSwitchManager
  • Fortinet FortiSASE
mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants)
CVE-2025-47855
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.

NVD description · AI analysis pending
9.8<1%
CVE-2025-64155
Unauthenticated RCE via OS Command Injection in Fortinet FortiSIEM

Fortinet FortiSIEM contains an unauthenticated OS command injection flaw (CWE-78) caused by improper neutralization of special elements used in an OS command. A remote attacker can trigger it by sending crafted TCP requests to the vulnerable service, requiring no credentials or user interaction. Successful exploitation allows execution of unauthorized code or commands on the SIEM host, giving an attacker control over a high-value security monitoring platform. Every current FortiSIEM release branch is affected: 7.4.0, 7.3.0 through 7.3.4, 7.1.0 through 7.1.8, 7.0.0 through 7.0.4, and 6.7.0 through 6.7.10. A public proof-of-concept exploit has been released, and EPSS assigns a 43.2% probability of exploitation within 30 days (99th percentile), though the flaw is not yet in CISA KEV and no confirmed in-the-wild exploitation has been reported.

Do: Upgrade FortiSIEM to the fixed release specified in Fortinet's advisory for CVE-2025-64155 as soon as possible, since exploitation requires only network reachability and no authentication. Until patched, restrict access to FortiSIEM's network-facing TCP services (management and event-ingestion interfaces) to trusted management networks and sources. Given the public proof-of-concept and high EPSS score, prioritize checking internet-exposed FortiSIEM instances for signs of exploitation and review logs for unexpected command execution.

9.845% PoC
  • Fortinet FortiSIEM 7.4.0
  • Fortinet FortiSIEM 7.3.0 - 7.3.4
  • Fortinet FortiSIEM 7.1.0 - 7.1.8
  • +2 more
largetens of thousands of FortiSIEM deployments worldwide (all current 6.7.x-7.4.x release branches affected)
Full article211 words · extracted from cyber.gc.ca · click to collapse

Serial number: AV26-023
Date: January 13, 2026
Updated: September 9, 2026

On January 13, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following:

  • FortiFone 7.0 – versions 7.0.0 to 7.0.1
  • FortiFone 3.0 – versions 3.0.13 to 3.0.23
  • FortiOS 7.6 – versions 7.6.0 to 7.6.3
  • FortiOS 7.4 – versions 7.4.0 to 7.4.8
  • FortiOS 7.2 – versions 7.2.0 to 7.2.11
  • FortiOS 7.0 – versions 7.0.0 to 7.0.17
  • FortiOS 6.4 – versions 6.4.0 to 6.4.16
  • FortiSASE 25.2 – version 25.2.b
  • FortiSASE 25.1.a – version 25.1.a.2
  • FortiSIEM 7.4 – version 7.4.0
  • FortiSIEM 7.3 – versions 7.3.0 to 7.3.4
  • FortiSIEM 7.2 – versions 7.2.0 to 7.2.6
  • FortiSIEM 7.1 – versions 7.1.0 to 7.1.8
  • FortiSIEM 7.0 – versions 7.0.0 to 7.0.4
  • FortiSIEM 6.7 – versions 6.7.0 to 6.7.10
  • FortiSwitchManager 7.2 – versions 7.2.0 to 7.2.6
  • FortiSwitchManager 7.0 – versions 7.0.0 to 7.0.5

Update 1

On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-25249 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-023