Skip to main content
QUIETLYTIC
Vulnerability

Fortinet FortiOS Vulnerability (CVE-2025-25249)

CVE-2025-25249, a high-severity CVSS 8.1 heap-based buffer overflow across multiple FortiOS versions, was added to CISA's KEV catalog on September 9, 2026.

CVE-2025-25249
Threat Level
HIGH
CVSS
8.1
Status
Active Exploitation
Confidence
Medium
Affected Products
Fortinet FortiOS, Fortinet FortiSwitchManager

CVE-2025-25249, a heap-based buffer overflow affecting multiple Fortinet FortiOS and FortiSwitchManager versions, was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026, confirming active exploitation. NVD scores the flaw CVSS 3.1 base 8.1 (high).

What the vulnerability does

NVD classifies CVE-2025-25249 under both CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write). Per NVD’s description, the flaw allows an attacker to execute unauthorized code or commands via specially crafted packets. The affected version ranges are broad, spanning multiple FortiOS release lines:

  • FortiOS: 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17, and all 6.4 versions
  • FortiSwitchManager: 7.2.0–7.2.6 and 7.0.0–7.0.5

The CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a network-reachable flaw requiring no privileges or user interaction, though attack complexity is rated high (unlike the Citrix and GitLab flaws covered in our other recent advisories, which were both low-complexity) — meaning successful exploitation depends on conditions an attacker doesn’t fully control, not a straightforward point-and-click exploit. Impact, if successful, is high across confidentiality, integrity, and availability.

Why it’s on KEV

CISA added CVE-2025-25249 to the KEV catalog on September 9, 2026. Fortinet’s own PSIRT advisory (FG-IR-25-084) is cited directly in NVD’s reference data, alongside a Siemens ProductCERT advisory covering the same flaw in Siemens products that incorporate Fortinet components. Under Binding Operational Directive (BOD) 26-04, affected organizations are directed to apply Fortinet’s fix and independently evaluate their own internet exposure.

What we don’t yet have

This record currently rests on a single source per field (NVD for CVSS/description/references, CISA KEV for title/vendor/product/mitigation metadata) — no second source has independently corroborated it yet, so confidence is medium, not high. NVD’s reference list also includes a third-party security-research blog post discussing this CVE in the context of a named remote-access-trojan campaign; we have not independently verified that reporting and are not repeating its specific claims here, only noting it exists as further reading via NVD’s own citation.

Why this matters

FortiOS runs on Fortinet’s FortiGate firewall/VPN appliance line, which — like the Citrix NetScaler flaw covered in our prior advisory — sits at the network perimeter by design. A code-execution vulnerability there, even with high attack complexity, is a serious risk for any organization running an affected version, particularly given the breadth of affected releases (essentially every actively maintained FortiOS branch except the newest patched point releases). Organizations should confirm their FortiOS/FortiSwitchManager versions against the affected ranges above and prioritize patching accordingly.

Frequently Asked Questions

What is CVE-2025-25249? A high-severity (CVSS 8.1) heap-based buffer overflow affecting multiple FortiOS and FortiSwitchManager version ranges, allowing code or command execution via specially crafted packets.

Is CVE-2025-25249 being actively exploited? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on September 9, 2026, which CISA only does when it has evidence of active exploitation.

Which Fortinet products are affected? FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17, and all 6.4 versions; FortiSwitchManager 7.2.0–7.2.6 and 7.0.0–7.0.5.

What should Fortinet administrators do? Apply the fix referenced in Fortinet’s PSIRT advisory FG-IR-25-084 and evaluate internet-facing exposure, consistent with CISA’s BOD 26-04 guidance for KEV-listed vulnerabilities.


Data sourced from the National Vulnerability Database (NVD) and CISA’s Known Exploited Vulnerabilities (KEV) catalog, aggregated September 9, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog

Related intelligence


Analyst tools