CVE-2025-25249 patch decisions are more urgent after current CISA-derived Known Exploited Vulnerabilities records identified the Fortinet flaw as known exploited. If your organisation operates an affected Fortinet product, the immediate job is to identify the exact product and software branch, move to an appropriate fixed release, and then separately assess whether exploitation may have occurred before remediation.
Direct answer: current KEV-derived records show CVE-2025-25249 entered the known-exploitation state on September 9, 2026. Fortinet’s own release documentation confirms that FortiOS 7.0.18, 7.2.12, 7.4.9 and 7.6.4 are fixed against CVE-2025-25249. Installing a fixed version closes the documented vulnerability for that release path, but it does not prove the device was never exploited before patching.
Why CVE-2025-25249 is more urgent now
CVE-2025-25249 was already a disclosed Fortinet vulnerability with vendor fixes available. The material change is the move to a known-exploitation state. That changes the administrator’s question from simply whether a patch exists to whether an exposed affected system requires urgent remediation and post-exploitation review.
Current KEV-derived records describe CVE-2025-25249 as a heap-based buffer overflow affecting Fortinet products and capable of allowing unauthorised code or command execution through crafted network traffic. Because exploitation is now part of the current evidence state, organisations should not treat the issue as a routine future maintenance item.
Which FortiOS versions are confirmed fixed?
Fortinet’s release notes directly identify several FortiOS releases as no longer vulnerable to CVE-2025-25249. The verified fixed releases reviewed by TPS are:
- FortiOS 7.0.18
- FortiOS 7.2.12
- FortiOS 7.4.9
- FortiOS 7.6.4
Administrators should match the deployed branch against current Fortinet documentation rather than assuming that one fixed version applies to every installation. A newer supported release in the same appropriate branch may also contain the fix, but the organisation should confirm the exact supported upgrade path before making a production change.
What about FortiSwitchManager and FortiSASE?
Current vulnerability records and reviewed security reporting also associate CVE-2025-25249 with FortiSwitchManager and FortiSASE. However, TPS was not able to retrieve the complete current Fortinet PSIRT advisory directly during this review. For those products, use Fortinet’s latest PSIRT matrix as the controlling source before selecting a target version.
This distinction matters because a FortiOS release-note confirmation should not be stretched into a complete affected-version matrix for every Fortinet product.
What administrators should do now
Inventory internet-facing and internally deployed Fortinet systems that could fall within the CVE-2025-25249 product scope. Record the exact product, software branch and build before changing anything.
Check whether the installed release is affected and identify the appropriate vendor-supported fixed release. For FortiOS, TPS directly verified fixes in 7.0.18, 7.2.12, 7.4.9 and 7.6.4.
Treat affected deployments as urgent because the vulnerability is now associated with known exploitation. Follow your change-control and availability requirements rather than applying an unsupported version blindly.
Do not erase useful logs, configuration state or other incident evidence before determining whether the system may have been exposed or exploited.
A successful software upgrade proves that the installed software state changed. It does not establish that exploitation never occurred before the upgrade. Review current Fortinet, CISA and organisational incident-response guidance for compromise indicators and investigation steps.
Recheck Fortinet and CISA if they publish new forensic indicators, affected-version corrections, mitigation changes or exploitation details.
Does being in CISA KEV mean your device was hacked?
No. Known Exploited Vulnerabilities status means there is evidence that the vulnerability has been exploited in the wild; it does not prove that every vulnerable appliance was compromised. Whether a particular system was exploited requires evidence from that environment.
This is why patch status and compromise status should be treated as two separate questions. The first asks whether the vulnerable software has been remediated. The second asks whether there is evidence that an attacker used the flaw before remediation.
Does patching alone close the incident?
Not necessarily. If an affected device was exposed during a period when exploitation was possible, applying the CVE-2025-25249 patch removes the known vulnerable state but does not automatically establish that credentials, configuration, persistence mechanisms or connected systems were untouched beforehand.
For an organisation with meaningful exposure, the safer workflow is to document the pre-patch state, complete the vendor-supported upgrade, review available logs and indicators, and escalate through the organisation’s incident-response process when compromise cannot be ruled out.
What does the CISA remediation date mean?
Current KEV-derived records show a September 12, 2026 remediation due date associated with CVE-2025-25249. CISA’s Binding Operational Directive requirements directly govern covered US federal civilian executive branch agencies. Private companies and organisations outside that scope should not read the federal date as a universal legal deadline.
For non-federal organisations, KEV inclusion is still a strong security-prioritisation signal because it indicates known exploitation, but the organisation’s legal and operational obligations depend on its own jurisdiction, contracts, policies and regulatory environment.
What is known about PivotC2 exploitation?
SOCRadar has reported exploitation of CVE-2025-25249 involving delivery of PivotC2. TPS has not established from the reviewed primary evidence that Fortinet or CISA confirmed that every exploitation campaign used PivotC2.
Therefore PivotC2 should be treated as a reported campaign detail, not as a universal indicator of CVE-2025-25249 exploitation. An organisation should not conclude that absence of a PivotC2 indicator proves its system was not targeted through the vulnerability.
Confirmed, reported and unresolved
Confirmed from Fortinet documentation: CVE-2025-25249 is fixed in the reviewed FortiOS releases 7.0.18, 7.2.12, 7.4.9 and 7.6.4.
Current KEV state: current CISA-derived KEV records identify CVE-2025-25249 as known exploited and added on September 9, 2026. Direct retrieval of the controlling CISA catalog entry was unavailable during TPS’s review.
Reported: SOCRadar reports exploitation involving PivotC2.
Still unresolved in this review: the complete current Fortinet PSIRT affected-and-fixed product matrix, authoritative victim count and geography, complete campaign attribution, and a final controlling set of compromise indicators applicable to every affected product.
Verification note
ThePulseSignal reviewed current CISA-derived KEV records, Fortinet’s official FortiOS release documentation and current security research about exploitation of CVE-2025-25249. Fortinet-fixed release claims are based on primary vendor documentation. The known-exploitation state is corroborated through current KEV-derived records because direct CISA retrieval returned an access error during this review. Campaign-specific details remain explicitly attributed rather than being presented as universal facts.



