Attackers are using a Fortinet software flaw to break into internet-facing devices and install remote-control malware. The bug, CVE-2025-25249, is an unauthenticated remote code execution vulnerability in FortiOS and FortiSwitchManager that Fortinet patched in January 2026. SOCRadar says more than 30,000 IPs were targeted and 178 devices were infected with the PivotC2 Node.js RAT, which gives shell access, tunneling, scanning, and configuration theft capabilities; CISA has now added the flaw to KEV.
Why it matters: Organizations running affected Fortinet gear should treat this as urgent because the flaw is already being exploited and can give attackers direct remote access to security infrastructure. Update immediately to patched versions, check exposed FortiGate and FortiSwitchManager systems for PivotC2 indicators, and investigate for data theft.
Ionut Arghire
2026.09.10
100% relevant
This article establishes a distinct story by tying a specific Fortinet CVE-2025-25249 to active exploitation, PivotC2 malware deployment, observed victim scope, and a new KEV listing.
← Back to all stories