CVE-2025-25249
published 2026-01-13CVE-2025-25249: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0…
PriorityP187critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-09-12
Exploited in the wild
EPSS
3.86%
89.9th percentile
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | >= 6.4.0 < 7.0.18 | 7.0.18 |
| fortinet | fortios | >= 7.2.0 < 7.2.12 | 7.2.12 |
| fortinet | fortios | 7.2.4 – 7.2.11 | — |
| fortinet | fortios | >= 7.4.0 < 7.4.9 | 7.4.9 |
| fortinet | fortios | 7.4.0 – 7.4.7 | — |
| fortinet | fortios | >= 7.6.0 < 7.6.4 | 7.6.4 |
| fortinet | fortios | 7.6.0 – 7.6.2 | — |
| fortinet | fortisase | — | — |
| fortinet | fortisase | — | — |
| fortinet | fortisase | — | — |
| fortinet | fortiswitchmanager | — | — |
| fortinet | fortiswitchmanager | >= 7.0.0 < 7.0.6 | 7.0.6 |
| fortinet | fortiswitchmanager | >= 7.2.0 < 7.2.7 | 7.2.7 |
| fortinet | fortiswitchmanager | 7.2.2 – 7.2.5 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mj8x-m8f5-x4w8: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7
ghsa_unreviewed·2026-01-13
CVE-2025-25249 [HIGH] CWE-122 GHSA-mj8x-m8f5-x4w8: A heap-based buffer overflow vulnerability in Fortinet FortiOS 7
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4.0 through 6.4.16, FortiSASE 25.2.b, FortiSASE 25.1.a.2, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
VulnCheck
Fortinet FortiOS Heap-based Buffer Overflow
vulncheck·2025·CVSS 9.8
CVE-2025-25249 [CRITICAL] Fortinet FortiOS Heap-based Buffer Overflow
Fortinet FortiOS Heap-based Buffer Overflow
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
Affected: Fortinet FortiOS
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/
CISA
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
cisa·2026-09-09·CVSS 9.8
CVE-2025-25249 [CRITICAL] CWE-122 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Vulnerability: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Affected: Fortinet Multiple Products
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD
Fortinet
Heap-based buffer overflow in cw_acd daemon
vendor_fortinet·2026-01-13·CVSS 8.1
CVE-2025-25249 [HIGH] CWE-122 Heap-based buffer overflow in cw_acd daemon
FG-IR-25-084: Heap-based buffer overflow in cw_acd daemon
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
CVEs: CVE-2025-25249
CWEs: CWE-122, CWE-787
CVSS: 8.1 (high)
Affected products: FortiOS, FortiSase, FortiSwitchManager, FortiSwitchmanager, Fortinet
No detection rules found.
No public exploits indexed.
Hackernews
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
blogs_hackernews·2026-09-10·CVSS 9.8
CVE-2026-20079 [CRITICAL] CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities ( KEV ) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
The vulnerabilities are listed below -
CVE-2026-20079 (CVSS score: 10.0) - An authentication bypass vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote atta
Wiz
CVE-2025-25249 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2025-25249 [HIGH] CVE-2025-25249 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-25249 :
FortiOS vulnerability analysis and mitigation
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
Source : NVD
## 9.8
Score
Published January 13, 2026
Severity CRITICAL
CNA Score 8.1
Affected Technologies
FortiOS
Fortinet FortiProxy
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:
2026-01-13
Published
2026-09-09
Added to CISA KEV
Exploited in the wild