What is CVE-2025-25249?
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
Timeline
- 2026-01-13Published to the U.S. National Vulnerability Database (NVD)
- 2026-09-09Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-09-10NVD record last updated
- 2026-09-12CISA federal remediation deadline (BOD 22-01)
CISA Known Exploited Vulnerability
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Affected product
Fortinet Multiple Products
NVD also lists CPE entries for: Fortinet Fortios, Fortinet Fortiswitchmanager, Fortinet Fortisase
Remediation Steps
- Identify systems affected by CVE-2025-25249 using vulnerability scanning tools
- Apply vendor patches according to the vendor's published security advisory
- Verify patch installation across all affected systems
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 1 of September 2026 (September 7 – 13)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.