## Overview
CISA added CVE-2025-25249 to its Known Exploited Vulnerabilities (KEV) list on September 9, 2026. This vulnerability affects multiple versions of Fortinet products, including FortiOS and FortiSwitchManager. The addition to the KEV list indicates a federal deadline for remediation due to evidence of active exploitation.
## Technical Details
CVE-2025-25249 is a heap-based buffer overflow vulnerability. It impacts FortiOS versions 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.0 through 7.0.17, and all versions of FortiOS 6.4. Additionally, FortiSwitchManager versions 7.2.0 through 7.2.6 and 7.0.0 through 7.0.5 are affected. Attackers can exploit this vulnerability by sending specially crafted packets to the affected systems, allowing them to execute unauthorized code or commands.
## Impact
The vulnerability carries a CVSS score of 9.8, indicating critical severity. Successful exploitation could lead to complete system compromise. This can result in unauthorized access to sensitive data, disruption of services, and potential lateral movement within affected networks.
## Mitigation
Fortinet has released patches for the affected versions. Organizations using these products should apply the updates immediately. Additionally, network segmentation and monitoring for unusual traffic patterns can help mitigate risks until patches are applied. Regularly reviewing security configurations and access controls is also recommended to reduce the attack surface.
CSURFACE Threat Sensor