news.mlab.sh
Back to the feed
vulnerability

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

CriticalCVSS 9.8
Summary

A critical remote code execution (RCE) vulnerability in Fortinet products is being actively exploited by threat actors to deploy the PivotC2 RAT. This allows attackers to gain remote access and control over vulnerable devices, leading to potential data exfiltration and further compromise. The vulnerability has been patched, but affected devices remain at risk until updated.

A high-severity remote code execution (RCE) vulnerability, tracked as CVE-2025-25249 with a CVSS score of 7.4, has been exploited by threat actors to deploy the PivotC2 RAT. The flaw is a heap-based buffer overflow that allows unauthenticated attackers to execute arbitrary code or commands via crafted requests. SOCRadar reported that hackers have been leveraging this vulnerability since at least July 2026, targeting over 30,000 IP addresses and infecting 178 devices. The attacks primarily targeted US entities, resulting in at least two instances of data exfiltration.

The vulnerability was initially identified and patched by Fortinet in January. Patches were released for FortiOS versions 7.6.4, 7.4.9, 7.2.12, and 7.0.18, and for FortiSwitchManager versions 7.2.7 and 7.0.6. The US Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and urged federal agencies to patch within three days. SOCRadar believes the PivotC2 RAT was likely developed with the use of AI, and that the attacks are being mounted by a Russian-speaking cybercrime actor.

Read the full article at SecurityWeek