CVE-2025-25249: Fortinet Heap Overflow Added to CISA KEV — Patch by September 12
CISA added CVE-2025-25249, a critical heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE, to the KEV catalog on 2026-09-09 with a due date of 2026-09-12. Treat internet-facing Fortinet appliances as urgent patch targets today.
CVE-2025-25249: Fortinet Heap Overflow Added to CISA KEV — Patch by September 12
TL;DR
CISA added CVE-2025-25249, a heap-based buffer overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE, to the Known Exploited Vulnerabilities (KEV) catalog on 2026-09-09, with a federal remediation due date of 2026-09-12. If you run affected Fortinet builds — especially internet-facing ones — inventory, patch, or mitigate today, and verify the fix before closing the ticket.
What is this vulnerability?
- CVE ID: CVE-2025-25249
- Vendor / product: Fortinet — FortiOS, FortiSwitchManager, and FortiSASE (multiple products)
- Vulnerability name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Weakness class: CWE-122 (Heap-based Buffer Overflow), CWE-787 (Out-of-bounds Write)
- Impact: An attacker can execute unauthorized code or commands via specially crafted packets.
- CISA KEV status: Yes — added 2026-09-09
- CISA due date: 2026-09-12
- Known ransomware use: Unknown per CISA
- Affected versions (per Fortinet advisory): FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17, and all 6.4 versions; FortiSwitchManager 7.2.0–7.2.6 and 7.0.0–7.0.5.
Severity signals from the reference intel: NVD rates this 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, while Fortinet's PSIRT rates it 8.1 (HIGH) with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The network attack vector and no-privilege requirement make perimeter exposure the primary triage concern.
KEV vs CVSS vs EPSS
| Signal | What it measures | How to use it for this CVE |
|---|---|---|
| CISA KEV | Confirmed in-the-wild exploitation; carries a binding remediation due date for federal agencies | This is the strongest signal here. CVE-2025-25249 is KEV-listed with a 2026-09-12 due date — prioritize it above non-KEV work regardless of other scores. |
| CVSS | Theoretical severity of the flaw (NVD 9.8 CRITICAL; Fortinet PSIRT 8.1 HIGH) | Use to justify urgency and change windows. The NVD vector shows network-reachable, no-auth, high impact — treat exposed Fortinet management/data interfaces as top tier. |
| EPSS | Probability of exploitation activity in the next 30 days (0.02403, ~83rd percentile) | EPSS is modest, but it does not override KEV. Use EPSS to sequence the long tail of non-KEV Fortinet CVEs, not to deprioritize this one. |
Step-by-step remediation
- Inventory affected assets. Search your CMDB and network scans for FortiOS (7.6.x, 7.4.x, 7.2.x, 7.0.x, and all 6.4), FortiSwitchManager (7.2.x, 7.0.x), and FortiSASE instances. Flag every internet-facing management or data interface.
- Patch or mitigate per vendor instructions. Apply the fixed builds and mitigations documented in Fortinet PSIRT advisory FG-IR-25-084. Follow CISA's required action: apply mitigations in accordance with vendor instructions and comply with BOD 26-04 guidance.
- Handle cloud and unavailable-mitigation cases. Per CISA, follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Assess exposure and triage forensics. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Where exposure is confirmed, follow CISA's Forensics Triage Requirements under BOD 26-04 implementation guidance.
- Verify the fix. Confirm the running firmware/version matches the vendor-fixed release, re-scan the asset, and validate that the management interface is no longer reachable from untrusted networks.
- Close the ticket with evidence. Record version before/after, patch timestamp, exposure status, and any forensic triage outcome. Retain artifacts for audit against the 2026-09-12 due date.
FAQ
Is CVE-2025-25249 in CISA KEV? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.
What is the CISA due date? The remediation due date is 2026-09-12. Federal agencies must remediate by then; other organizations should treat it as an urgent internal SLA.
Is this vulnerability internet-facing?
The NVD vector (AV:N) indicates network-reachable exploitation, and CISA directs stakeholders to evaluate each asset's internet exposure. Assume any internet-facing Fortinet interface running an affected version is at risk until patched.
Is there a ransomware tie? CISA lists known ransomware use as Unknown for this CVE. That does not lower urgency — KEV status alone reflects confirmed exploitation.
Which products and versions are affected? FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17, and all 6.4 versions; FortiSwitchManager 7.2.0–7.2.6 and 7.0.0–7.0.5; and FortiSASE. Check Fortinet's advisory for the exact fixed builds.
What is the weakness type? A heap-based buffer overflow (CWE-122) with out-of-bounds write characteristics (CWE-787), exploitable via specially crafted packets to run unauthorized code or commands.