CISA added CVE-2025-25249, a heap-overflow vulnerability in Fortinet FortiOS, to its Known Exploited Vulnerabilities catalog after identifying active exploitation, The Hacker News reported. Attackers are using the flaw to deliver a newly identified Node.js-based remote access trojan dubbed PivotC2, which has infected 178 devices to date, the majority located in the United States.
The disclosure was part of a broader CISA KEV update covering multiple actively exploited network-perimeter vulnerabilities, with a federal patch deadline tied to the update.
Why it matters: FortiOS underpins firewall and VPN infrastructure across a large share of small and mid-sized enterprise and critical-infrastructure networks. A newly identified, purpose-built RAT delivered through an actively exploited perimeter flaw is a strong signal that organizations running FortiOS should treat this patch as time-sensitive rather than routine.
Source: The Hacker News, September 10, 2026, citing CISA KEV catalog update.

Leave a Reply