Skip to main content
CyberSingle-sourceHighDevelopingFeatured
7.4

Fortinet CVE-2025-25249 Exploited in PivotC2 RAT Attacks

A high-severity, unauthenticated code execution vulnerability in Fortinet products (CVE-2025-25249), patched in January 2026, is now being actively exploited in attacks deploying the PivotC2 remote access trojan. The exploitation indicates a gap between patch availability and deployment, leaving unpatched systems exposed. This matters because Fortinet devices are widely used in enterprise and government networks, and successful exploitation could lead to network compromise and lateral movement.

SecurityWeekabout 22 hours agoengCredibility 44%View source

Score Breakdown

Mosaic Score7.4
Confidence0.7
Significance0.8
Source credibility0.4
Source

Related signals

8 found