logo

Heap-Based Buffer Overflow in Fortinet Products

ID: b739e79e-03b8-5e0a-b608-8c5802dc798a

STIX ID: report--b739e79e-03b8-5e0a-b608-8c5802dc798a

Feed Name: Kudelski Security

Threat Score
85/100

Date Published: 2026-01-15

Date Updated: 2026-07-22

...
...

A critical heap-based buffer overflow (CVE-2025-25249) has been disclosed in multiple Fortinet products (FortiOS, FortiSwitchManager, FortiSASE) allowing unauthenticated remote code execution via the cw_acd daemon; Fortinet has released patches and provided temporary configuration workarounds, and the Cyber Fusion Center is monitoring the situation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.