Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2025-25249 2026-09-09

Fortinet Heap Overflow CVE-2025-25249 Added to CISA KEV Under Active Exploitation

"CISA added CVE-2025-25249, a pre-auth heap-based buffer overflow across Fortinet FortiOS, FortiSwitchManager, and FortiSASE, to the Known Exploited Vulnerabilities catalog on 2026-09-09, with a three-day remediation…"

CISA added CVE-2025-25249, a pre-auth heap-based buffer overflow across Fortinet FortiOS, FortiSwitchManager, and FortiSASE, to the Known Exploited Vulnerabilities catalog on 2026-09-09, with a three-day remediation deadline.

What Is It

CVE-2025-25249 is a heap-based buffer overflow (CWE-122, with NVD also assigning CWE-787, out-of-bounds write) in Fortinet FortiOS, FortiSwitchManager, and FortiSASE. An attacker can execute unauthorized code or commands by sending specially crafted packets to an affected device.

Scoring is split. Fortinet PSIRT rates it CVSS 3.1 8.1 (HIGH) with high attack complexity: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. NVD rates it 9.8 (CRITICAL) with low attack complexity: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Both agree on network attack vector, no privileges, no user interaction, and total confidentiality/integrity/availability impact.

Why It Matters

CISA's KEV listing confirms active exploitation in the wild. The accompanying SSVC decision records exploitation status as active, automatable as no, and technical impact as total. Ransomware campaign use is listed as Unknown.

The affected products are network edge and management devices reachable over the network with no authentication required, and the KEV entry flags forensic triage as required (forensicTriage: Yes), meaning compromise assessment, not just patching, is in scope.

CISA's KEV entry is the only exploitation source this brief relies on. No specific tooling, malware family, or named threat actor is attributed to exploitation of CVE-2025-25249 by any source cited here.

What's Vulnerable

Per the NVD description:

NVD CPE ranges indicate fixes at FortiOS 6.4.17, 7.0.18, 7.2.12, 7.4.9, and 7.6.4. Siemens RUGGEDCOM APE1808 is also listed as affected via a third-party advisory.

Patch Status

KEV due date is 2026-09-12: three days after listing. Required action: apply mitigations per vendor instructions in compliance with CISA BOD 26-04 and the Forensics Triage Requirements. For cloud services, follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines.

Sources