EXPLOITED

Fortinet CVE-2025-25249 on CISA KEV. PivotC2 RAT riding unauth RCE.

Heap overflow patched in January is now KEV-listed. SOCRadar: 30k+ IPs targeted, 178 FortiGate devices infected with a Node.js post-ex RAT — mostly US.

Sep 10, 2026 · 3 min read

CISA added CVE-2025-25249 to KEV with a three-day federal remediation window (aligned to BOD 26-04). The bug is a heap-based buffer overflow in FortiOS / FortiSwitchManager that Fortinet described as allowing remote unauthenticated code execution via crafted requests. CVSS score cited in coverage: 7.4. Patches shipped in January 2026: FortiOS 7.6.4 / 7.4.9 / 7.2.12 / 7.0.18 and FortiSwitchManager 7.2.7 / 7.0.6.

SOCRadar reports threat actors have been exploiting the flaw to deploy PivotC2, a Node.js FortiGate post-exploitation RAT (interactive shell, tunneling, scanning, config harvest), with activity since at least July 2026. Company figures, per SOCRadar: more than 30,000 IPs targeted, 178 devices infected; mainly US entities; at least two intrusions with data exfiltration; likely Russian-speaking cybercrime. No named APT or ransomware brand beyond that attribution.

Underwrite sheet — sourced only: CVE-2025-25249 unauth RCE (patched Jan 2026); CISA KEV this week; PivotC2 RAT per SOCRadar (30k+ IPs / 178 infected). Primary actions: confirm FortiOS/FortiSwitchManager build, patch, and hunt for post-exploitation. SecurityWeek for the SOCRadar framing.

Sources