Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

🚨SEVERITY: HIGH — CVSS 8.1Security Advisory

TL;DR 📌

  • Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
  • Highest CVSS: 8.1 (High).
  • Listed in CISA KEV (2026-09-09) — this is being exploited in the wild.
  • Fixed in 7.0.18, 7.0.6, 7.2.12, 7.2.7 — upgrade to this release or later.
  • CVEs: CVE-2025-25249.

What it is

CVE-2025-25249 is a heap-based buffer overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE. Specially crafted packets sent to the affected component trigger the overflow, allowing execution of unauthorised code or commands.

The CVSS vector (AV:N/AC:H/PR:N/UI:N) indicates the flaw is reachable over the network without authentication or user interaction, though attack complexity is rated high — the attacker needs specific conditions to be met to land the crafted packets correctly. Given the “packets” wording and the affected product list, this points at a network-facing processing path rather than the administrative GUI, though the advisory should be consulted for the precise service or port involved.

Affected versions per the advisory are FortiOS 7.6.0 through 7.6.3, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.0 through 7.0.17, and 6.4 all versions; FortiSwitchManager 7.2.0 through 7.2.6 and 7.0.0 through 7.0.5. FortiSASE is also named as affected in Fortinet’s summary, but no specific version range for it is listed — check the FortiSASE section of the advisory directly.

This CVE is listed in CISA’s Known Exploited Vulnerabilities catalogue, added 9 September 2026, meaning it is known to be exploited.

What to do

  • Patch FortiOS to 7.6.4, 7.4.9, 7.2.12, or 7.0.18 depending on your current branch (7.6.x, 7.4.x, 7.2.x, or 7.0.x respectively).
  • Patch FortiSwitchManager to 7.2.7 (from 7.2.0–7.2.6) or 7.0.6 (from 7.0.0–7.0.5).
  • For FortiOS 6.4, no fixed version is listed in the advisory data at hand — check Fortinet’s advisory directly for guidance, as this branch may require migration to a supported release rather than an in-branch fix.
  • For FortiSASE deployments, consult Fortinet’s advisory for the applicable fixed release, since specific version numbers aren’t given here.
  • Given this CVE’s presence in CISA KEV, treat patching as urgent rather than scheduled maintenance — prioritise internet-facing FortiOS and FortiSwitchManager instances first.
  • Where immediate patching isn’t possible, review Fortinet’s advisory for any interim mitigations or workarounds it lists, and restrict network exposure of the affected management and processing interfaces in the meantime.

For leadership 🧭

Executive summary. Fortinet firewalls, switch management servers and FortiSASE deployments running affected versions can be compromised remotely by an unauthenticated attacker sending crafted packets, with no user interaction required. This is already in CISA’s Known Exploited Vulnerabilities catalogue, so it needs to be treated as an active risk rather than routine patching.

Why it matters:

  • The flaw sits in a network-facing packet-processing path in FortiOS and FortiSwitchManager, not behind a login screen, so any reachable interface is a potential attack surface
  • No authentication or user interaction is needed to trigger the overflow, and the CVSS impact score (C:H/I:H/A:H) means a successful attack can fully compromise confidentiality, integrity and availability of the device
  • FortiOS 6.4 has no listed fixed version, meaning affected devices on that branch may need migration to a supported release rather than a simple patch
  • Confirmed presence in CISA’s KEV catalogue means this vulnerability is known to be exploited, raising the urgency for any internet-facing FortiOS or FortiSwitchManager instance

Now / Next / Later:

  • Now: Identify every FortiOS, FortiSwitchManager, and FortiSASE instance in your estate and check its version against the affected ranges, prioritising anything internet-facing.
  • Next: Patch FortiOS to 7.6.4, 7.4.9, 7.2.12 or 7.0.18 as appropriate, and FortiSwitchManager to 7.2.7 or 7.0.6, in the next available change window; for FortiOS 6.4 and FortiSASE, follow Fortinet’s advisory for migration or fix guidance since no version numbers are provided here.
  • Later: Build a standing process for tracking Fortinet KEV listings and restrict exposure of FortiOS and FortiSwitchManager network-facing interfaces so future packet-processing flaws have a smaller blast radius while patches are rolled out.

Source