๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Summary
Fortinet's FortiOS, FortiSwitchManager, and FortiSASE products contain a heap-based buffer overflow vulnerability (a flaw where attackers write too much data into a memory area, causing crashes or code execution), allowing attackers to run unauthorized code through specially crafted packets. This vulnerability is currently being exploited by real attackers in the wild. Organizations must apply vendor-provided mitigations by September 12, 2026, following CISA's BOD 26-04 guidance on prioritizing security updates by risk.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions at https://fortiguard.fortinet.com/psirt/FG-IR-25-084, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk guidance. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and ensure adherence to BOD 26-04 patching guidelines.
Vulnerability Details
EPSS: 0.8%
Yes
๐ฅ Actively Exploited
September 8, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-25249
First tracked: September 9, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%