CISA has added CVE-2025-25249 to its Known Exploited Vulnerabilities (KEV) catalogue. The vulnerability affects Fortinet’s FortiOS, FortiSwitchManager and FortiSASE products. Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability allows attackers to execute unauthorised code or commands using specially crafted packets.
The flaw is a heap-based buffer overflow. Attackers can exploit it through specially crafted packets, potentially achieving unauthorised code or command execution. The vulnerability has a CVSS score of 7.4 and is rated High. Patch availability is currently unknown.
CISA has confirmed active exploitation, as reflected by the CVE’s inclusion in the KEV catalogue. The available data does not confirm use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate the vulnerability by 12 September 2026.
CISA requires organisations to apply mitigations in accordance with Fortinet’s instructions, BOD 26-04 guidance and CISA’s Forensics Triage Requirements. For cloud services, organisations should follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. FCEB agencies are directly affected, but all organisations should assess their exposure, particularly for internet-facing assets, and review applicable patching requirements.
See the NVD entry and CISA KEV catalogue for full details.