HIGHVulnerability
Verified
Global

CISA KEV: Fortinet Multiple Products — Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

Analysis

Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-09. Remediation due: 2026-09-12.

Indicators of Compromise (1)

CVE (1)
CVE-2025-25249
Source Attribution

Originally published by CISA KEV on Sep 9, 2026. Verified by: CISA.

Related Threats