What Changed
SOCRadar reports that Russian-speaking cybercrime actors have been exploiting CVE-2025-25249—an unauthenticated heap-based buffer overflow in the FortiOS and FortiSwitchManager cw_acd (CAPWAP) daemon—to deploy PivotC2, a Node.js remote access trojan purpose-built for FortiGate post-exploitation. Fortinet advisory FG-IR-25-084 states the bug may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted requests, while noting that ASLR and PIE raise exploit complexity. Patches shipped in January 2026.
Score the severity carefully in triage meetings: Fortinet rates the issue CVSS 7.4; NVD and SOCRadar cite 9.8. That disagreement is material for prioritization debates—exploitation status is not. CISA added CVE-2025-25249 to KEV on September 9, 2026 with a compressed BOD 26-04 window and forensic-triage expectations for internet-exposed assets.
Victim counts (SOCRadar-derived): attackers targeted more than 30,000 IP addresses; SOCRadar reports 178 devices infected with PivotC2, concentrated in the United States, with at least two intrusions progressing to confirmed data exfiltration. Treat these figures as SOCRadar’s campaign telemetry, not a global census. Reported PivotC2 capabilities include interactive shell, traffic tunneling, network scanning, and configuration or credential harvesting.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Why This Matters Operationally
Perimeter firewalls that speak CAPWAP on UDP 5246–5249—especially with fabric or CAPWAP access enabled on internet-facing interfaces—are the entry condition. Once PivotC2 lands, operators lose the assumption that “the FortiGate is the trusted chokepoint.” Unauthenticated RCE on firewall OS plus a native RAT observed since at least July 2026 closes the 7.4-versus-9.8 debate for anyone still waiting.
What Defenders Should Verify First
- Patch to FortiOS 7.6.4, 7.4.9, 7.2.12, or 7.0.18+ (migrate off all FortiOS 6.4) and FortiSwitchManager 7.2.7 or 7.0.6+ per FG-IR-25-084.
- Inventory internet exposure of CAPWAP-CONTROL (UDP 5246–5249) on fabric-enabled interfaces; apply Fortinet’s local-in policy guidance to allow only trusted CAPWAP peers if you cannot patch immediately—then still patch.
- Forensically triage internet-exposed FortiGates for activity from July 2026 onward: unexpected Node.js processes, unauthorized admin/VPN/wireless accounts, config diffs, tunneling artifacts, and credential or cloud-bucket exfil patterns associated with follow-on intrusions.
- Do not let the CVSS split slow patching—KEV plus an in-the-wild RAT is the decision signal.
Source Context
- Fortinet FG-IR-25-084 (CVE-2025-25249)
- SecurityWeek: Fortinet flaw exploited in PivotC2 RAT attacks
- CISA KEV: CVE-2025-25249 added September 9, 2026
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.