CVE Tools
Back to feed
Exploited in the wild FortiOS rce FortiSwitchManager Fortinet zero-day

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

SecurityWeek·By Ionut Arghire··1 min read
CVE Tools coverage

SOCRadar has reported active exploitation of CVE-2025-25249, an unauthenticated remote code execution vulnerability in Fortinet's FortiOS and FortiSwitchManager products. Attackers are leveraging this heap-based buffer overflow flaw to install the PivotC2 RAT, which grants them persistent access through features like traffic tunneling and network scanning. The incident has impacted 178 devices across over 30,000 targeted IPs, primarily affecting US entities and resulting in data exfiltration in at least two cases. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, prompting urgent patch recommendations to versions 7.6.4, 7.4.9, 7.2.12, and 7.0.18 for FortiOS, and 7.2.7 and 7.0.6 for FortiSwitchManager.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store