CVE-2025-32756
published 2025-05-13CVE-2025-32756: A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2025-06-04
Exploited in the wild
EPSS
31.42%
98.1th percentile
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
Affected
48 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | forticamera | — | — |
| fortinet | forticamera | — | — |
| fortinet | forticamera | 1.1.0 – 1.1.5 | — |
| fortinet | forticamera | 2.1.0 – 2.1.3 | — |
| fortinet | forticamera_firmware | 1.1.0 – 1.1.5 | — |
| fortinet | forticamera_firmware | 2.0.0 – 2.1.3 | — |
| fortinet | forticamerafirmware | — | — |
| fortinet | fortimail | — | — |
| fortinet | fortimail | >= 7.0.0 < 7.0.9 | 7.0.9 |
| fortinet | fortimail | 7.0.0 – 7.0.8 | — |
| fortinet | fortimail | >= 7.2.0 < 7.2.8 | 7.2.8 |
| fortinet | fortimail | 7.2.0 – 7.2.7 | — |
| fortinet | fortimail | >= 7.4.0 < 7.4.5 | 7.4.5 |
| fortinet | fortimail | 7.4.0 – 7.4.4 | — |
| fortinet | fortimail | >= 7.6.0 < 7.6.3 | 7.6.3 |
| fortinet | fortimail | 7.6.0 – 7.6.2 | — |
| fortinet | fortindr | — | — |
| fortinet | fortindr | — | — |
| fortinet | fortindr | — | — |
| fortinet | fortindr | — | — |
| fortinet | fortindr | — | — |
| fortinet | fortindr | — | — |
| fortinet | fortindr | — | — |
| fortinet | fortindr | — | — |
| fortinet | fortindr | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for 'fcgi debugging' toggled on (non-default) on Fortinet devices — this is an attacker-set indicator used to log credentials from the system or SSH login attempts. ↗
- →Hunt for evidence of system crashlogs deletion on Fortinet devices, used by threat actors to cover their tracks post-exploitation. ↗
- →Detect newly added cron jobs on Fortinet devices — threat actors deployed cron jobs designed to harvest credentials post-exploitation. ↗
- →Monitor for unexpected network scanning scripts dropped on Fortinet devices, indicating post-exploitation lateral movement activity. ↗
- →Inspect inbound HTTP requests to Fortinet administrative interfaces for malformed or oversized hash cookie values as the exploit vector. ↗
- ·Disabling the HTTP/HTTPS administrative interface on vulnerable Fortinet devices is the recommended mitigation for those unable to immediately patch. ↗
- ·The 'fcgi debugging' feature is NOT enabled by default; its presence on a device is a strong indicator of compromise. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fcpx-h44g-vx2x: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiVoice versions 7
ghsa_unreviewed·2025-05-13
CVE-2025-32756 [CRITICAL] CWE-121 GHSA-fcpx-h44g-vx2x: A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiVoice versions 7
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiVoice versions 7.2.0, 7.0.0 through 7.0.6, 6.4.0 through 6.4.10, FortiRecorder versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.5, 6.4.0 through 6.4.5, FortiMail versions 7.6.0 through 7.6.2, 7.4.0 through 7.4.4, 7.2.0 through 7.2.7, 7.0.0 through 7.0.8, FortiNDR versions 7.6.0, 7.4.0 through 7.4.7, 7.2.0 through 7.2.4, 7.0.0 through 7.0.6, FortiCamera versions 2.1.0 through 2.1.3, 2.0 all versions, 1.1 all versions, allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.
VulnCheck
Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
vulncheck·2025·CVSS 9.8
CVE-2025-32756 [CRITICAL] CWE-124 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.
Affected: Fortinet Multiple Products
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://fortiguard.fortinet.com/psirt/FG-IR-25-254; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.rapid7.com/blog/post/2025/05/14/etr-multiple-fortinet-products-cve-2025-32756-exp
CISA
Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
cisa·2025-05-14·CVSS 9.8
CVE-2025-32756 [CRITICAL] CWE-124 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Vulnerability: Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Affected: Fortinet Multiple Products
Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-254 ; https://nvd.nist.gov/vuln/detail/CVE-2025-32756
Remediation Due Date: 2025-06-04
Fortinet
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa...
vendor_fortinet·2025-05-13·CVSS 9.8
CVE-2025-32756 [CRITICAL] CWE-121 A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa...
FG-IR-25-254: A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa...
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or c
Suricata
ET WEB_SPECIFIC_APPS Fortinet Admin API Stack-based Buffer Overflow in AuthHash Cookie (CVE-2025-32756)
suricata·2025-06-13·CVSS 9.8
CVE-2025-32756 [CRITICAL] ET WEB_SPECIFIC_APPS Fortinet Admin API Stack-based Buffer Overflow in AuthHash Cookie (CVE-2025-32756)
ET WEB_SPECIFIC_APPS Fortinet Admin API Stack-based Buffer Overflow in AuthHash Cookie (CVE-2025-32756)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Fortinet Admin API Stack-based Buffer Overflow in AuthHash Cookie (CVE-2025-32756)"; flow:established,to_server; http.uri; bsize:16; content:"/module/admin.fe"; fast_pattern; http.cookie; content:"authhash"; nocase; pcre:"/^(?:\x3d|\x253[dD])[^\s\x26]{24,}/R"; reference:url,horizon3.ai/attack-research/attack-blogs/cve-2025-32756-low-rise-jeans-are-back-and-so-are-buffer-overflows/; reference:cve,2025-32756; classtype:web-application-attack; sid:2062929; rev:1; metadata:attack_target Server, created_at 2025_06_13, cve CVE_2025_32756, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, t
No public exploits indexed.
Tenable
CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild
blogs_tenable·2026-04-06·CVSS 9.8
[CRITICAL] CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2025-64155 PoC released Command Injection Vulnerability
blogs_tenable·2026-01-14·CVSS 9.8
[CRITICAL] CVE-2025-64155 PoC released Command Injection Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2025-64446 FortiWeb Zero-Day Exploited
blogs_tenable·2025-11-14·CVSS 9.8
[CRITICAL] CVE-2025-64446 FortiWeb Zero-Day Exploited
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Wiz
What is a buffer overflow? Modern attacks and cloud security | Wiz
blogs_wiz·2025-10-30
What is a buffer overflow? Modern attacks and cloud security | Wiz
## What is a buffer overflow?
A buffer overflow is a well-known type of memory corruption vulnerability. When a program tries to write more data into a buffer (a temporary storage space) than it was allocated, the excess data “overflows,” overwriting adjacent memory locations.
This isn't a new flaw; buffer overflows have been around for decades. But they remain a dangerous and relevant threat, even in modern applications and systems. In the cloud, buffer overflow attacks can target services like web APIs or applications running in containers.
Two out-of-bounds access vulnerabilities CWE Top 25 Most Dangerous Software Weaknesses list for 2024: CWE-787 (Out-of-bounds Write) and CWE-125 (Out-of-bounds Read). Not every vulnerability is actually exploited in the wild, of course. But a recent
Wiz
What is a buffer overflow? Modern attacks and cloud security | Wiz
blogs_wiz·2025-10-30
What is a buffer overflow? Modern attacks and cloud security | Wiz
## What is a buffer overflow?
A buffer overflow is a well-known type of memory corruption vulnerability. When a program tries to write more data into a buffer (a temporary storage space) than it was allocated, the excess data “overflows,” overwriting adjacent memory locations.
This isn't a new flaw; buffer overflows have been around for decades. But they remain a dangerous and relevant threat, even in modern applications and systems. In the cloud, buffer overflow attacks can target services like web APIs or applications running in containers.
Two out-of-bounds access vulnerabilities CWE Top 25 Most Dangerous Software Weaknesses list for 2024: CWE-787 (Out-of-bounds Write) and CWE-125 (Out-of-bounds Read). Not every vulnerability is actually exploited in the wild, of course. But a recent
Tenable
CVE-2025-25256: Proof of Concept Released for Critical Fortinet FortiSIEM Command Injection Vulnerability
blogs_tenable·2025-08-13·CVSS 9.8
[CRITICAL] CVE-2025-25256: Proof of Concept Released for Critical Fortinet FortiSIEM Command Injection Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cybersecurity Snapshot: AI Security Tools Embraced by Cyber Teams, Survey Finds, as Vulnerability Research Gets a Boost from UK Cyber Agency
blogs_tenable·2025-07-18
Cybersecurity Snapshot: AI Security Tools Embraced by Cyber Teams, Survey Finds, as Vulnerability Research Gets a Boost from UK Cyber Agency
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Where Capability Meets Opportunity: Introducing the Tenable Research Special Operations Team
blogs_tenable·2025-05-28
Where Capability Meets Opportunity: Introducing the Tenable Research Special Operations Team
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
19th May – Threat Intelligence Report
blogs_checkpoint·2025-05-19
CVE-2025-31324 19th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 19th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 19th May, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Fashion giant Dior confirmed a data breach that exposed customer information from its Fashion and Accessories line. The leaked data includes names, gender, phone numbers, email addresses, postal addresses, and purchase history with customers in South Korea and China most affected. Specific details regarding the quantity and addit
Tenable
CVE-2025-32756: Zero-Day Vulnerability in Multiple Fortinet Products Exploited in the Wild
blogs_tenable·2025-05-14·CVSS 9.8
[CRITICAL] CVE-2025-32756: Zero-Day Vulnerability in Multiple Fortinet Products Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Fortinet fixes critical zero-day exploited in FortiVoice attacks
blogs_bleepingcomputer·2025-05-13·CVSS 9.8
CVE-2025-32756 [CRITICAL] Fortinet fixes critical zero-day exploited in FortiVoice attacks
## Fortinet fixes critical zero-day exploited in FortiVoice attacks
## Sergiu Gatlan
Fortinet released security updates to patch a critical remote code execution vulnerability exploited as a zero-day in attacks targeting FortiVoice enterprise phone systems.
The security flaw is a stack-based overflow vulnerability tracked as CVE-2025-32756 that also impacts FortiMail, FortiNDR, FortiRecorder, and FortiCamera.
As the company explains in a security advisory issued on Tuesday, successful exploitation can allow remote unauthenticated attackers to execute arbitrary code or commands via maliciously crafted HTTP requests.
Fortinet's Product Security Team discovered CVE-2025-32756 based on attackers' activity, including network scans, system crashlogs deletion to cover their tracks, and 'fcgi
Wiz
CVE-2025-55717 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.4
CVE-2025-55717 [MEDIUM] CVE-2025-55717 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-55717 :
Fortimail vulnerability analysis and mitigation
A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6 may allow an authenticated malicious administrator to obtain user's secrets via CLI commands. Practical exploitability is limited by conditions out of the control of the attacker: An admin must log in to the targeted device.
Source : NVD
## 4
Score
Published March 10, 2026
Severity MEDIUM
CNA Score 4.0
Affected Technologies
Fortimail
Has Public Explo
2025-05-13
Published
2025-05-14
Added to CISA KEV
Exploited in the wild