ZeroHour
Story · 1 source · 1 articlefirst updated ()

CISA adds actively exploited Fortinet CVE-2025-25249 to KEV amid PivotC2 RAT attacks; Fortinet patches 10 flaws including critical FortiMonitorOnSight and FortiPAM auth…

What's new: New detail added: Fortinet's September patch release fixes 10 vulnerabilities, including critical auth flaws CVE-2026-84390 (CVSS 9.6, JWT forgery/reuse bypass in the FortiMonitorOnSight web portal) and CVE-2026-84388 (CVSS 9.1, FortiPAM Chrome extension flaw requiring coordinated upgrades to FortiPAM 1.9.1/1.8.4 and extension 8.0.1.123+). Added: high-severity fixes CVE-2026-26084 (FortiSandbox…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

CISA added the actively exploited Fortinet heap-based buffer overflow CVE-2025-25249 (CVSS 7.4) to its KEV catalog on September 9, 2026, with a September 12 federal patch deadline, as SOCRadar reports 178 devices infected with the PivotC2 RAT; Fortinet's…

CISA added CVE-2025-25249, a heap-based buffer overflow (CWE-122/CWE-787) in the Fortinet cw_acd daemon that allows unauthenticated remote code execution by sending specially crafted packets, to its Known Exploited Vulnerabilities catalog on September 9, 2026. The flaw carries a CVSS score of 7.4 (though one source labels it critical) and affects FortiOS and FortiSwitchManager, with one source also citing FortiSASE; it was patched in January 2026 in FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6. Under BOD 26-04, federal agencies face a three-day remediation deadline of September 12, 2026, plus mandatory forensic triage of affected environments; ransomware use is currently listed as unknown. SOCRadar reports that attackers scanned more than 30,000 IP addresses, infected 178 devices with the PivotC2 RAT, and exfiltrated data in at least two intrusions primarily targeting US entities, attributing the campaign to a likely Russian-speaking cybercrime actor and suggesting the RAT is AI-assisted and has been in use since July 2026. In its updated AV26-023 advisory, the Canadian Centre for Cyber Security flagged related January 2026 Fortinet flaws: CVE-2025-47855 (unauthenticated local configuration access) and CVE-2025-64155 (unauthenticated remote command injection), spanning FortiFone, FortiOS, FortiSASE, FortiSIEM, and FortiSwitchManager. Separately, Fortinet's September patch release fixes 10 vulnerabilities, including CVE-2026-84390 (CVSS 9.6), a sensitive-information flaw in the FortiMonitorOnSight web portal that lets unauthenticated attackers bypass authentication with forged or reused JWTs, and CVE-2026-84388 (CVSS 9.1), an improper authentication flaw in the FortiPAM Privileged Access Agent Chrome extension that lets attackers proxy a user's browser traffic via a malicious website and requires coordinated upgrades to FortiPAM 1.9.1/1.8.4 and extension 8.0.1.123+. High-severity fixes also cover FortiSandbox information disclosure (CVE-2026-26084) and man-in-the-middle risk in the FortiOS/FortiProxy Agentless ZTNA portal (CVE-2026-84393), alongside medium/low issues across FortiManager, FortiAnalyzer, FortiSOAR, FortiClient, FortiSIEM and others; Fortinet did not indicate any of these flaws are being exploited in the wild. The Canadian Centre's advisory AV26-898 relays the Fortinet PSIRT bulletins covering FortiOS 7.6.1-7.6.6, FortiProxy 7.6.2-7.6.6, FortiPAM Chrome extensions 7.4/8.0, FortiSandbox 4.4/5.0, FortiSandbox Cloud and…

  • CISA added CVE-2025-25249, a heap-based buffer overflow (CWE-122/CWE-787) in the Fortinet cw_acd daemon, to its Known Exploited Vulnerabilities catalog on September 9, 2026.
  • CVE-2025-25249 (CVSS 7.4) allows unauthenticated remote code execution via specially crafted packets; sources disagree on severity labeling, with one calling it critical despite the reported CVSS 7.4 score.
  • Under BOD 26-04, federal agencies face a September 12, 2026 remediation deadline plus mandatory forensic triage of affected environments; ransomware use is currently listed as unknown.
  • CVE-2025-25249 affects FortiOS and FortiSwitchManager per patch records, with one source also citing FortiSASE; fixes shipped in January 2026 in FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6.
  • SOCRadar reports attackers scanned over 30,000 IP addresses, infected 178 devices with the PivotC2 RAT, and exfiltrated data in at least two intrusions, primarily targeting US entities.
  • SOCRadar attributes the campaign to a likely Russian-speaking cybercrime actor and suggests the RAT is AI-assisted and has been in use since July 2026.
  • Canadian Centre advisory AV26-023 (Update 1) flags related January 2026 Fortinet flaws CVE-2025-47855 (unauthenticated local configuration access) and CVE-2025-64155 (unauthenticated remote command injection) across FortiFone, FortiOS,…
  • Fortinet's September patch release fixes 10 vulnerabilities, including critical authentication flaws CVE-2026-84390 (CVSS 9.6) in the FortiMonitorOnSight web portal and CVE-2026-84388 (CVSS 9.1) in the FortiPAM Privileged Access Agent…

Coverage timeline

  1. · 7d ago
    Canadian Centre for Cyber Security· 26
    Fortinet security advisory (AV26-898)

    Canadian Cyber Centre advisory AV26-898 flags Fortinet vulnerabilities across FortiOS, FortiProxy, FortiPAM, FortiSandbox and FortiMonitorOnSight, urging administrators to apply updates

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25249
Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE

CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known.

Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product.

9.82% KEV PoC
  • Fortinet FortiOS
  • Fortinet FortiSwitchManager
  • Fortinet FortiSASE
mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants)
CVE-2025-47855
An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23

An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests.

NVD description · AI analysis pending
9.8<1%
CVE-2025-64155
Unauthenticated RCE via OS Command Injection in Fortinet FortiSIEM

Fortinet FortiSIEM contains an unauthenticated OS command injection flaw (CWE-78) caused by improper neutralization of special elements used in an OS command. A remote attacker can trigger it by sending crafted TCP requests to the vulnerable service, requiring no credentials or user interaction. Successful exploitation allows execution of unauthorized code or commands on the SIEM host, giving an attacker control over a high-value security monitoring platform. Every current FortiSIEM release branch is affected: 7.4.0, 7.3.0 through 7.3.4, 7.1.0 through 7.1.8, 7.0.0 through 7.0.4, and 6.7.0 through 6.7.10. A public proof-of-concept exploit has been released, and EPSS assigns a 43.2% probability of exploitation within 30 days (99th percentile), though the flaw is not yet in CISA KEV and no confirmed in-the-wild exploitation has been reported.

Do: Upgrade FortiSIEM to the fixed release specified in Fortinet's advisory for CVE-2025-64155 as soon as possible, since exploitation requires only network reachability and no authentication. Until patched, restrict access to FortiSIEM's network-facing TCP services (management and event-ingestion interfaces) to trusted management networks and sources. Given the public proof-of-concept and high EPSS score, prioritize checking internet-exposed FortiSIEM instances for signs of exploitation and review logs for unexpected command execution.

9.845% PoC
  • Fortinet FortiSIEM 7.4.0
  • Fortinet FortiSIEM 7.3.0 - 7.3.4
  • Fortinet FortiSIEM 7.1.0 - 7.1.8
  • +2 more
largetens of thousands of FortiSIEM deployments worldwide (all current 6.7.x-7.4.x release branches affected)
CVE-2026-26084
Improper Access Control in Fortinet FortiSandbox Exposes Sensitive Data

CVE-2026-26084 is an improper access control flaw (CWE-284) in the web interface of Fortinet's FortiSandbox threat-analysis product line, affecting on-premises 4.4.x and 5.0.x releases as well as the FortiSandbox Cloud and PaaS offerings. An unauthenticated attacker can trigger it remotely by sending crafted HTTP requests to the affected FortiSandbox web service, bypassing access controls without needing credentials or user interaction. A successful attacker gains access to sensitive information handled by the appliance; Fortinet's critical 9.9 CVSS score also reflects a scope change with a high availability-impact component, so defenders should treat the practical impact as potentially broader than simple information disclosure. Any organization running affected versions of FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS is in scope, though the product's enterprise appliance/cloud deployment model means the affected population is far smaller than endpoint or firewall software. There is no evidence of exploitation so far: the flaw is not in CISA KEV, has no known public proof-of-concept, and EPSS assigns roughly a 0.2% probability of exploitation within 30 days.

Do: Upgrade all FortiSandbox deployments to a fixed release outside the affected ranges — later than 5.0.5 on the 5.0 branch, later than 4.4.8 on the 4.4 branch, and later than 5.0.5 for Cloud and PaaS — following Fortinet's PSIRT advisory. Until patched, restrict HTTP/HTTPS management access to the appliance to trusted management networks or VPN, since the flaw is reachable without authentication. Monitor Fortinet's advisory and the CISA KEV catalog for updates, given the critical severity score.

9.9<1%
  • Fortinet FortiSandbox 5.0.0 through 5.0.5
  • Fortinet FortiSandbox 4.4.0 through 4.4.8
  • Fortinet FortiSandbox Cloud 5.0.4 through 5.0.5
  • +1 more
moderatelikely on the order of several thousand to ~10,000 deployed FortiSandbox appliances/instances worldwide, with only a smaller subset exposing the vulnerable web…
CVE-2026-84388

NVD description · AI analysis pending
CVE-2026-84390
Sensitive Information in Source Code in Fortinet FortiMonitorOnSight (CVSS 9.8)

CVE-2026-84390 is a critical (CVSS 3.1: 9.8) information-disclosure flaw in Fortinet FortiMonitorOnSight in which sensitive information is included in the product's source code (CWE-540). An unauthenticated, network-located attacker who obtains that embedded material (e.g., secrets or credentials shipped with the code) can use it to gain improper access by subverting access controls; the CVSS vector requires no privileges or user interaction and rates the impact high on confidentiality, integrity, and availability. All FortiMonitorOnSight deployments running the affected 7.2.x releases listed by Fortinet (7.2.0 through 7.2.2 and 7.2.4 through 7.2.7) are affected. Fortinet has shipped fixes for this flaw, but there is no public proof-of-concept, the vulnerability is not in CISA KEV, and no exploitation in the wild is currently known.

Do: Upgrade FortiMonitorOnSight to a fixed release per Fortinet's PSIRT advisory, i.e., any version superseding the listed 7.2.0-7.2.2 and 7.2.4-7.2.7 ranges. Because the flaw involves sensitive material in source code, also rotate any credentials, keys, or secrets associated with the deployment and review logs for signs of unauthenticated access. Until patched, restrict network exposure of the OnSight management interface to trusted networks only.

9.8
  • Fortinet FortiMonitorOnSight 7.2.0 through 7.2.2
  • Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7
nichelikely on the order of a few thousand deployments worldwide (estimate; no public install counts)
CVE-2026-84393
Certificate Host-Mismatch Validation Flaw in FortiOS and FortiProxy ZTNA

CVE-2026-84393 is an improper certificate validation flaw (CWE-297, host mismatch) in the ZTNA (Zero Trust Network Access) functionality of Fortinet FortiOS and FortiProxy, in which certificates are not correctly verified against the intended host. Per the related advisory headline, a network-adjacent or on-path attacker can exploit it to perform a man-in-the-middle attack against ZTNA connections, and the vendor describes the impact as information disclosure; the CVSS vector additionally rates confidentiality, integrity, and availability impact as high. Organizations running affected FortiOS 7.6.1 through 7.6.6 or FortiProxy 7.6.2 through 7.6.6 with ZTNA enabled are exposed. As of now there is no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at just 0.2% (5th percentile), so risk is currently low but patching is still warranted given the high CVSS score.

Do: Inventory FortiOS and FortiProxy deployments for versions 7.6.1–7.6.6 / 7.6.2–7.6.6 and prioritize upgrades to a fixed release listed in Fortinet's PSIRT advisory for this CVE (fixed versions are not specified in the available data). Until patched, treat ZTNA sessions on affected devices as susceptible to on-path interception and restrict or monitor ZTNA use, particularly for untrusted or public network paths. No public exploit or in-the-wild exploitation is known, so this can be handled in a normal patch cycle rather than emergency change.

8.1<1%
  • Fortinet FortiOS 7.6.1 through 7.6.6
  • Fortinet FortiProxy 7.6.2 through 7.6.6
largeon the order of tens of thousands of gateways (a subset of the roughly 300,000+ internet-visible Fortinet devices, limited to those running the 7.6 branch with…