Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [cve, fortinet, buffer-overflow, kev] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government] ยท au_impact: true

CVE-2025-25249 is a heap-based buffer overflow vulnerability in multiple Fortinet products (including FortiGate), added to the CISA Known Exploited Vulnerabilities (KEV) catalogue on 9 September 2026. Its addition to KEV signals confirmed in-the-wild exploitation, meaning US federal civilian agencies were ordered to remediate, and Australian/NZ organisations running affected Fortinet edge devices should treat patching as urgent given the network-perimeter positioning of FortiGate appliances.

Attribute Detail
CVE CVE-2025-25249
Type Heap-based buffer overflow
Exploited In the wild (KEV added 2026-09-09)
Vendor Fortinet
Source CISA KEV โ€” Tier 1/4

Source