New PivotC2 RAT Delivered via Exploited Fortinet FortiOS Heap Overflow, Infects 178 Devices

CISA added CVE-2025-25249, a heap-overflow vulnerability in Fortinet FortiOS, to its Known Exploited Vulnerabilities catalog after identifying active exploitation, The Hacker News reported. Attackers are using the flaw to deliver a newly identified Node.js-based remote access trojan dubbed PivotC2, which has infected 178 devices to date, the majority located in the United States.

The disclosure was part of a broader CISA KEV update covering multiple actively exploited network-perimeter vulnerabilities, with a federal patch deadline tied to the update.

Why it matters: FortiOS underpins firewall and VPN infrastructure across a large share of small and mid-sized enterprise and critical-infrastructure networks. A newly identified, purpose-built RAT delivered through an actively exploited perimeter flaw is a strong signal that organizations running FortiOS should treat this patch as time-sensitive rather than routine.

Source: The Hacker News, September 10, 2026, citing CISA KEV catalog update.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *