← Back to blog
Blog Detail

CVE-2025-25249: Fortinet Heap Overflow Added to CISA KEV — Patch by September 12

CISA added CVE-2025-25249, a critical heap-based buffer overflow in FortiOS, FortiSwitchManager, and FortiSASE, to the KEV catalog on 2026-09-09 with a due date of 2026-09-12. Treat internet-facing Fortinet appliances as urgent patch targets today.

Trusteed Team
Trusteed Editorial
Written On
Sep 18, 2026
Category
CTEM
Read Time
4 min read
  • CVE-2025-25249
  • KEV
  • CISA
  • Fortinet
  • FortiOS
  • FortiSwitchManager
  • FortiSASE
  • heap-based buffer overflow
  • CWE-122
  • CWE-787
  • BOD 26-04

CVE-2025-25249: Fortinet Heap Overflow Added to CISA KEV — Patch by September 12

TL;DR

CISA added CVE-2025-25249, a heap-based buffer overflow in Fortinet FortiOS, FortiSwitchManager, and FortiSASE, to the Known Exploited Vulnerabilities (KEV) catalog on 2026-09-09, with a federal remediation due date of 2026-09-12. If you run affected Fortinet builds — especially internet-facing ones — inventory, patch, or mitigate today, and verify the fix before closing the ticket.

What is this vulnerability?

  • CVE ID: CVE-2025-25249
  • Vendor / product: Fortinet — FortiOS, FortiSwitchManager, and FortiSASE (multiple products)
  • Vulnerability name: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
  • Weakness class: CWE-122 (Heap-based Buffer Overflow), CWE-787 (Out-of-bounds Write)
  • Impact: An attacker can execute unauthorized code or commands via specially crafted packets.
  • CISA KEV status: Yes — added 2026-09-09
  • CISA due date: 2026-09-12
  • Known ransomware use: Unknown per CISA
  • Affected versions (per Fortinet advisory): FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17, and all 6.4 versions; FortiSwitchManager 7.2.0–7.2.6 and 7.0.0–7.0.5.

Severity signals from the reference intel: NVD rates this 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, while Fortinet's PSIRT rates it 8.1 (HIGH) with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The network attack vector and no-privilege requirement make perimeter exposure the primary triage concern.

KEV vs CVSS vs EPSS

Signal What it measures How to use it for this CVE
CISA KEV Confirmed in-the-wild exploitation; carries a binding remediation due date for federal agencies This is the strongest signal here. CVE-2025-25249 is KEV-listed with a 2026-09-12 due date — prioritize it above non-KEV work regardless of other scores.
CVSS Theoretical severity of the flaw (NVD 9.8 CRITICAL; Fortinet PSIRT 8.1 HIGH) Use to justify urgency and change windows. The NVD vector shows network-reachable, no-auth, high impact — treat exposed Fortinet management/data interfaces as top tier.
EPSS Probability of exploitation activity in the next 30 days (0.02403, ~83rd percentile) EPSS is modest, but it does not override KEV. Use EPSS to sequence the long tail of non-KEV Fortinet CVEs, not to deprioritize this one.

Step-by-step remediation

  1. Inventory affected assets. Search your CMDB and network scans for FortiOS (7.6.x, 7.4.x, 7.2.x, 7.0.x, and all 6.4), FortiSwitchManager (7.2.x, 7.0.x), and FortiSASE instances. Flag every internet-facing management or data interface.
  2. Patch or mitigate per vendor instructions. Apply the fixed builds and mitigations documented in Fortinet PSIRT advisory FG-IR-25-084. Follow CISA's required action: apply mitigations in accordance with vendor instructions and comply with BOD 26-04 guidance.
  3. Handle cloud and unavailable-mitigation cases. Per CISA, follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
  4. Assess exposure and triage forensics. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Where exposure is confirmed, follow CISA's Forensics Triage Requirements under BOD 26-04 implementation guidance.
  5. Verify the fix. Confirm the running firmware/version matches the vendor-fixed release, re-scan the asset, and validate that the management interface is no longer reachable from untrusted networks.
  6. Close the ticket with evidence. Record version before/after, patch timestamp, exposure status, and any forensic triage outcome. Retain artifacts for audit against the 2026-09-12 due date.

FAQ

Is CVE-2025-25249 in CISA KEV? Yes. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

What is the CISA due date? The remediation due date is 2026-09-12. Federal agencies must remediate by then; other organizations should treat it as an urgent internal SLA.

Is this vulnerability internet-facing? The NVD vector (AV:N) indicates network-reachable exploitation, and CISA directs stakeholders to evaluate each asset's internet exposure. Assume any internet-facing Fortinet interface running an affected version is at risk until patched.

Is there a ransomware tie? CISA lists known ransomware use as Unknown for this CVE. That does not lower urgency — KEV status alone reflects confirmed exploitation.

Which products and versions are affected? FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17, and all 6.4 versions; FortiSwitchManager 7.2.0–7.2.6 and 7.0.0–7.0.5; and FortiSASE. Check Fortinet's advisory for the exact fixed builds.

What is the weakness type? A heap-based buffer overflow (CWE-122) with out-of-bounds write characteristics (CWE-787), exploitable via specially crafted packets to run unauthorized code or commands.

Related resources

Join Our Newsletter

Trusteed keeps you informed: emerging risks, platform updates, and practical guides for faster defense.