Fortinet Releases Security Updates for FortiOS and FortiSwitch Manager
Advisory addresses a vulnerability which if exploited could allow a remote unauthenticated attacker to perform arbitrary code or command execution
Summary
Advisory addresses a vulnerability which if exploited could allow a remote unauthenticated attacker to perform arbitrary code or command execution
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2025-25249
Security researchers have reported active exploitation of CVE-2025-25249 in the wild to deploy PivotC2 malware. The National Vulnerability Database has reclassified the CVSS score of this vulnerability to 9.8.
Introduction
Fortinet has released security updates to address a high severity vulnerability in FortiOS and FortiSwitch Manager. Successful exploitation by a remote unauthenticated attacker could allow for arbitrary code or command execution.
- CVE-2025-25249 - Heap-Based Buffer Overflow vulnerability - CVSSv3 score: 9.8
Threat updates
| Date | Update |
|---|---|
| 9 Sep 2026 |
CVE-2025-25249 CVSS Score Reclassified from 7.4 to 9.8
The following has been updated to reflect this change:
|
Remediation advice
Affected organisations are encouraged to review the Fortinet PSIRT FG-IR-25-084 and apply the relevant updates as soon as possible.
Definitive source of threat updates
Last edited: 9 September 2026 12:09 pm