ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire1
Part of a story covered by 4 sources: “Fortinet CVE-2025-25249 Exploited to Deploy PivotC2 RAT; CISA Adds Flaw to KEV Catalog” — merged summary and timeline →

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

highExploit / PoC exploited in the wildimportance 82CVE-2025-25249
AI summary · glm-5.3-flash

Threat actors exploit Fortinet heap-based buffer overflow CVE-2025-25249 to deploy PivotC2 RAT, infecting 178 devices and exfiltrating data from US targets.

SOCRadar reports exploitation of an unauthenticated remote code execution vulnerability, CVE-2025-25249 (CVSS 7.4), patched in January in FortiOS and FortiSwitchManager. Attackers scanned over 30,000 IP addresses, infected 178 devices with PivotC2 RAT, and at least two intrusions resulted in data exfiltration, primarily targeting US entities. SOCRadar attributes attacks to a likely Russian-speaking cybercrime actor and suggests the RAT was AI-assisted, in use since July 2026. CISA added the CVE to the KEV catalog with a three-day BOD 26-04 patch deadline for federal agencies.

  • CVE-2025-25249 (CVSS 7.4) is a heap-based buffer overflow allowing unauthenticated RCE
  • 178 devices infected with PivotC2 RAT after 30,000+ IP addresses targeted
  • Two US intrusions confirmed with data exfiltration
  • CISA added CVE to KEV with three-day federal patch deadline
  • Patch available in FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25249
Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known.

Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product.

9.82% KEV PoC
  • Fortinet FortiOS
  • Fortinet FortiSwitchManager
  • Fortinet FortiSASE
mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants)
Full article300 words · extracted from securityweek.com · click to collapse

Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a Node.js RAT, SOCRadar reports.

Tracked as CVE-2025-25249 (CVSS score of 7.4) and described as a heap-based buffer overflow issue, the high-severity bug was patched in January in FortiOS and FortiSwitchManager.

The flaw “may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests,” Fortinet noted in its advisory.

This week, SOCRadar warned that hackers have been exploiting the security defect to deploy the PivotC2 RAT on vulnerable devices.

A FortiGate post-exploitation tool, the backdoor provides attackers with interactive shell access, traffic tunneling, network scanning, and configuration harvesting capabilities.

SOCRadar believes that PivotC2 was likely developed with the use of AI and that threat actors have been using it in attacks since at least July 2026.

Advertisement. Scroll to continue reading.

“The threat actors targeted more than 30,000 IP addresses, leading to the exploitation and infection of 178 devices with PivotC2,” SOCRadar says.

The attacks mainly targeted US entities, where at least two intrusions have resulted in data exfiltration.

According to the cybersecurity firm, the attacks are likely mounted by a Russian-speaking cybercrime actor.

On Wednesday, the US cybersecurity agency CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within three days, in line with BOD 26-04’s requirements.

Patches for the bug were rolled out in FortiOS versions 7.6.4, 7.4.9, 7.2.12, and 7.0.18, and in FortiSwitchManager versions 7.2.7 and 7.0.6. All organizations are advised to update to these or newer versions.

Related: Android’s September 2026 Updates Patch 180 Vulnerabilities

Related: Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories

Related: Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

Related: ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks/