ZeroHour
Story · 1 source · 1 articlefirst updated ()

CISA Flags Actively Exploited Fortinet CVE-2025-25249 as Unverified '1-Day' FortiGate SSL VPN Exploit Is Offered Underground

criticalExploit / PoCexploited in the wildimportance 85CVE-2025-25249CVE-2024-21762
What's new: This is the first merged summary. Between the two reports: on September 9, 2026 (reported September 10), CISA added CVE-2025-25249 to the KEV catalog, imposing a September 12 federal remediation deadline under BOD 26-04 with mandatory forensic triage. By September 17, an unverified underground listing had surfaced offering a claimed FortiGate SSL VPN '1-day' RCE exploit for FortiOS 7.2.x/7.4.x,…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

CISA added actively exploited Fortinet CVE-2025-25249, a critical unauthenticated heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE, to its KEV catalog on September 9, 2026 with a September 12 federal remediation deadline under BOD…

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) allowing unauthorized code execution by sending specially crafted packets, affecting FortiOS, FortiSwitchManager, and FortiSASE. Per the second report, the flaw was patched in January 2026 but has been exploited in real attacks since July 2026. CISA added it to the Known Exploited Vulnerabilities catalog on September 9, 2026, setting a September 12, 2026 remediation deadline for federal agencies under BOD 26-04, with mandatory forensic triage of affected environments rather than routine patching alone. Internet-facing Fortinet firewalls and SASE platforms are considered a likely foothold for credential theft, persistence, and lateral movement; ransomware use is currently listed as unknown. A second flaw, CVE-2024-21762, a critical out-of-bounds write in the FortiOS and FortiProxy SSL VPN component, continues to be abused against exposed FortiGate systems. In a separate, unverified development, Dark Web Intelligence shared an advertisement for a private '1-day' remote code execution exploit targeting FortiGate SSL VPN appliances on FortiOS 7.2.x and 7.4.x, with a claimed proof-of-concept video but no CVE, firmware builds, or technical details; the listing could reflect a new flaw, a patched bug, or fraud. Fortinet has advised disabling SSL VPN where immediate upgrades are not possible.

  • CVE-2025-25249 is an unauthenticated heap-based buffer overflow (CWE-122/CWE-787) in FortiOS, FortiSwitchManager, and FortiSASE that enables code execution via specially crafted packets
  • CVE-2025-25249 was patched in January 2026 but has been exploited in real attacks since July 2026
  • CISA added CVE-2025-25249 to the KEV catalog on September 9, 2026, with a September 12, 2026 patch deadline for federal agencies under BOD 26-04 and mandatory forensic triage of affected environments
  • CVE-2024-21762, a critical out-of-bounds write in the FortiOS and FortiProxy SSL VPN component, continues to be abused against exposed FortiGate systems
  • An unverified underground listing offers a claimed private '1-day' FortiGate SSL VPN RCE exploit for FortiOS 7.2.x and 7.4.x with a claimed PoC video; no CVE, affected builds, or technical details were provided, so it may be a new flaw, a…
  • Internet-facing Fortinet firewalls and SASE platforms are a likely foothold for credential theft, persistence, and lateral movement; ransomware use is currently listed as unknown
  • Fortinet advises disabling SSL VPN where immediate upgrades are not possible

Coverage timeline

  1. · 7d ago
    Cyber Security News· 85
    CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks

    CISA added actively exploited Fortinet CVE-2025-25249, a critical heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE, to its KEV catalog.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21762
Out-of-Bounds Write RCE in Fortinet FortiOS and FortiProxy

CVE-2024-21762 is a critical (CVSS 9.8) out-of-bounds write (CWE-787) in the SSL VPN functionality of Fortinet FortiOS and FortiProxy, allowing an unauthenticated remote attacker to execute unauthorized code or commands by sending specifically crafted requests to the vulnerable service. No authentication or user interaction is required, and network access to the SSL VPN interface is the only precondition. Organizations running affected FortiOS versions (on FortiGate appliances) or any affected FortiProxy version are exposed, particularly where the SSL VPN is internet-facing. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-02-09 with ransomware use noted, EPSS puts the 30-day exploitation probability at 84.3%, and public scans suggest roughly 150,000 internet-exposed Fortinet devices may be impacted.

Do: Upgrade FortiOS and FortiProxy to fixed releases outside the affected ranges per Fortinet's advisory, prioritizing internet-facing devices; as an interim mitigation, disable SSL VPN (or SSL VPN web mode) where it is not required, per vendor and CISA guidance. After patching, check for signs of compromise and rotate credentials, since Fortinet has warned that attackers retained access to FortiGate devices post-patching. The flaw is in CISA KEV with known ransomware use, so treat this as an urgent patching priority.

9.884% KEV ransomware
  • Fortinet FortiOS 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17
  • Fortinet FortiProxy 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7
mass≈150,000 internet-exposed FortiGate/FortiProxy devices (public internet-wide scans)
CVE-2025-25249
Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known.

Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product.

9.82% KEV PoC
  • Fortinet FortiOS
  • Fortinet FortiSwitchManager
  • Fortinet FortiSASE
mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants)