Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
Summary
A high-severity, unauthenticated code execution vulnerability in Fortinet products, tracked as CVE-2025-25249, has been exploited in attacks utilizing the PivotC2 RAT. The vulnerability was patched in January 2026.
IFF Assessment
The exploitation of a critical vulnerability by a RAT indicates a successful attack by malicious actors, posing a threat to defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 12, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching this vulnerability on affected Fortinet devices, as it is actively being exploited by malware. Monitoring for PivotC2 RAT activity and ensuring robust endpoint detection and response (EDR) capabilities are crucial to mitigate the risk of compromise.