CVE-2025-25249: Fortinet Multiple Products
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
- Vendor
- Fortinet
- Product
- Multiple Products
- Vulnerability
- Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
- Date added
- Sep 9, 2026
- CISA due date (U.S. federal agencies)
- Sep 12, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-122, CWE-787
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02