Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Summary

A high-severity, unauthenticated code execution vulnerability in Fortinet products, tracked as CVE-2025-25249, has been exploited in attacks utilizing the PivotC2 RAT. The vulnerability was patched in January 2026.

IFF Assessment

FOE

The exploitation of a critical vulnerability by a RAT indicates a successful attack by malicious actors, posing a threat to defenders.

Severity

8.1 High

CISA KEV: Listed as actively exploited. Federal patch due: September 12, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching this vulnerability on affected Fortinet devices, as it is actively being exploited by malware. Monitoring for PivotC2 RAT activity and ensuring robust endpoint detection and response (EDR) capabilities are crucial to mitigate the risk of compromise.

Read Full Story →