CISA Adds Actively Exploited Fortinet Flaw CVE-2025-25249 to KEV; PivotC2 RAT Attacks Infected 178 Devices
CISA added Fortinet CVE-2025-25249, a heap-based buffer overflow (CVSS 7.4) enabling unauthenticated remote code execution, to its KEV catalog on September 9, 2026, giving federal agencies until September 12, 2026 to patch under BOD 26-04. SOCRadar reports…
CISA added CVE-2025-25249, a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet's cw_acd daemon that allows unauthorized code execution via specially crafted packets, to its Known Exploited Vulnerabilities catalog on September 9, 2026. Federal agencies face a three-day remediation deadline of September 12, 2026 under BOD 26-04, and CISA requires mandatory forensic triage of affected environments rather than routine patching alone. The Canadian Centre for Cyber Security relayed the KEV addition in an update to its advisory AV26-023, which covers January 2026 Fortinet advisories. SOCRadar analysis of the in-the-wild exploitation found attackers scanned more than 30,000 IP addresses and infected 178 devices with the PivotC2 RAT, with at least two intrusions at primarily US entities resulting in data exfiltration; SOCRadar attributes the attacks to a likely Russian-speaking cybercrime actor and suggests the RAT was AI-assisted and in use since July 2026. Internet-facing Fortinet firewalls and SASE platforms are seen as a likely foothold for credential theft, persistence, and lateral movement, though ransomware use is currently listed as unknown. The sources disagree slightly on affected product scope: SecurityWeek says the flaw was patched in January in FortiOS and FortiSwitchManager, while Cyber Security News also lists FortiSASE; fixes are available in FortiOS 7.6.4, 7.4.9, 7.2.12, and 7.0.18, and FortiSwitchManager 7.2.7 and 7.0.6. The same advisory set also covers CVE-2025-47855 (unauthenticated local configuration access) and CVE-2025-64155 (unauthenticated remote command injection).
- CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in the cw_acd daemon allowing unauthenticated remote code execution via specially crafted packets; CVSS 7.4 (per SecurityWeek/SOCRadar).
- CISA added CVE-2025-25249 to the KEV catalog on September 9, 2026, with a September 12, 2026 patch deadline for federal agencies under BOD 26-04 (three days) and mandatory forensic triage of affected environments.
- SOCRadar: attackers scanned over 30,000 IP addresses and infected 178 devices with the PivotC2 RAT; at least two intrusions, primarily targeting US entities, involved data exfiltration.
- SOCRadar attributes the attacks to a likely Russian-speaking cybercrime actor and suggests the PivotC2 RAT was AI-assisted and in use since July 2026.
- Affected products: SecurityWeek reports the flaw was patched in January in FortiOS and FortiSwitchManager; Cyber Security News also lists FortiSASE — the sources disagree on scope. CCCS advisory AV26-023 relays January 2026 Fortinet…
- Fixes available in FortiOS 7.6.4, 7.4.9, 7.2.12, and 7.0.18, and FortiSwitchManager 7.2.7 and 7.0.6.
- Related Fortinet flaws in the same advisory set: CVE-2025-47855 (unauthenticated local configuration access) and CVE-2025-64155 (unauthenticated remote command injection).
- Internet-facing Fortinet firewalls and SASE platforms are viewed as a likely foothold for credential theft, persistence, and lateral movement; ransomware use is currently listed as unknown.
Coverage timelineoldest first · each row is one article
- · 7d agoFortinet security advisory (AV26-023) - Update 1
Canadian Centre for Cyber Security· 60
CISA added Fortinet CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon, to its KEV catalog; Canadian Cyber Centre urges patching.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-25249 | Heap-Based Buffer Overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE CVE-2025-25249 is a heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE that allows an attacker to execute unauthorized code or commands. It is triggered by sending specially crafted packets to an affected device, causing an out-of-bounds write in heap memory that can be leveraged for code execution. Successful exploitation gives attackers command execution on the appliance; in observed intrusions against FortiGate firewalls, attackers have deployed custom Node.js malware and a post-exploitation RAT dubbed PivotC2. Any organization running the affected Fortinet products is at risk, with internet-facing FortiGate firewalls the primary concern. The flaw was added to CISA's KEV on 2026-09-09, confirming active exploitation in the wild (ransomware use unknown); no public PoC is known. Do: Upgrade FortiOS, FortiSwitchManager, and FortiSASE in accordance with Fortinet's advisory (specific fixed versions are not listed in the available data), prioritizing internet-exposed FortiGate firewalls per CISA KEV and BOD 26-04 timelines. Hunt for signs of compromise, including custom Node.js malware and the PivotC2 RAT, on FortiGate devices, and review exposure and access logs for admin/SSL-VPN interfaces. If patching is not possible, apply vendor-recommended mitigations or, per BOD 26-04, discontinue use of the exposed product. | 9.8 | 2% | KEV PoC |
| mass≈300,000–500,000 internet-exposed FortiGate/FortiOS devices (plus FortiSASE cloud tenants) | |
| CVE-2025-47855 | An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 through 7.0.1, FortiFone 3.0.13 through 3.0.23 allows an unauthenticated attacker to obtain the device configuration via crafted HTTP or HTTPS requests. NVD description · AI analysis pending | 9.8 | <1% | — | — | ||
| CVE-2025-64155 | Unauthenticated RCE via OS Command Injection in Fortinet FortiSIEM Fortinet FortiSIEM contains an unauthenticated OS command injection flaw (CWE-78) caused by improper neutralization of special elements used in an OS command. A remote attacker can trigger it by sending crafted TCP requests to the vulnerable service, requiring no credentials or user interaction. Successful exploitation allows execution of unauthorized code or commands on the SIEM host, giving an attacker control over a high-value security monitoring platform. Every current FortiSIEM release branch is affected: 7.4.0, 7.3.0 through 7.3.4, 7.1.0 through 7.1.8, 7.0.0 through 7.0.4, and 6.7.0 through 6.7.10. A public proof-of-concept exploit has been released, and EPSS assigns a 43.2% probability of exploitation within 30 days (99th percentile), though the flaw is not yet in CISA KEV and no confirmed in-the-wild exploitation has been reported. Do: Upgrade FortiSIEM to the fixed release specified in Fortinet's advisory for CVE-2025-64155 as soon as possible, since exploitation requires only network reachability and no authentication. Until patched, restrict access to FortiSIEM's network-facing TCP services (management and event-ingestion interfaces) to trusted management networks and sources. Given the public proof-of-concept and high EPSS score, prioritize checking internet-exposed FortiSIEM instances for signs of exploitation and review logs for unexpected command execution. | 9.8 | 45% | PoC |
| largetens of thousands of FortiSIEM deployments worldwide (all current 6.7.x-7.4.x release branches affected) |