501/69 Friday, September 11, 2026

Researchers from SOCRadar reported exploitation of CVE-2025-25249, a vulnerability with a CVSS score of 7.4 in FortiOS and FortiSwitchManager, to install PivotC2 malware on FortiGate devices. The vulnerability is a heap-based buffer overflow flaw that could allow unauthenticated attackers to execute commands through specially crafted data. Fortinet released patches for the vulnerability in January 2026, and reports indicate that exploitation in real-world attacks has been observed since July 2026.
PivotC2 is a Node.js-based control malware used to manage compromised FortiGate devices. It supports interactive shell access, tunnel and proxy creation, internal network scanning, and collection of device configuration data. SOCRadar stated that the attackers targeted more than 30,000 IP addresses and identified 178 devices that had been exploited and infected with PivotC2. Data exfiltration was also observed in at least two investigated incidents.
CISA has added CVE-2025-25249 to its Known Exploited Vulnerabilities (KEV) Catalog after confirming evidence of active exploitation. Administrators should update FortiOS to version 7.6.4, 7.4.9, 7.2.12, or 7.0.18, or later, depending on the release branch in use, and update FortiSwitchManager to version 7.2.7 or 7.0.6, or later. They should also inspect internet-exposed devices and review connections or abnormal activity that may be associated with PivotC2.
Source: https://www.securityweek.com/fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks/
