Vulnerabilities
A FortiGate flaw patched in January is being exploited to install remote access malware
CISA has added a FortiOS flaw that Fortinet fixed in January to its catalogue of exploited vulnerabilities. According to SOCRadar, it has been used since July to install PivotC2, a backdoor on the firewall itself. If your company has a FortiGate, the question is simple: is it up to date?
Fortinet — Vendor of the affected product (FortiOS and FortiSwitchManager)

In 30 seconds
- The flaw (CVE-2025-25249) affects FortiOS and FortiSwitchManager and lets an attacker with no credentials run code on the device. Fortinet fixed it in January 2026.
- CISA added it to its catalogue of actively exploited vulnerabilities on 9 September.
- According to SOCRadar, cited by SecurityWeek, it has been exploited since at least July to install PivotC2, a backdoor giving remote access to the firewall. 178 devices infected; the attacks mainly targeted the US.
- The FortiOS 6.4 branch has no fix: you need to migrate to a supported version.
Does this affect me?
It affects you if your company has a FortiGate firewall (or switches managed with FortiSwitchManager) that hasn't been updated to a fixed version since January. In many SMEs the firewall was installed by the IT provider years ago and nobody knows which version it runs: if that's your case, this is the week to ask. No Spanish victims have been confirmed.
What happened
On 9 September 2026, the US cybersecurity agency (CISA) added CVE-2025-25249 to its catalogue of actively exploited vulnerabilities (KEV). It is a memory overflow flaw in a component of FortiOS —the operating system of FortiGate firewalls— and of FortiSwitchManager.
Fortinet describes it like this in its advisory: the vulnerability "may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests". The vendor released the fix on 13 January 2026.
The day after CISA's decision, SecurityWeek reported the analysis of security firm SOCRadar: the flaw has been used since at least July 2026 to install PivotC2, a backdoor built for FortiGate that gives attackers remote access to the device and lets them tunnel traffic, scan the internal network and extract the firewall's configuration.
What we know
- Affected versions (according to Fortinet): FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17 and the entire 6.4 branch, as well as FortiSwitchManager 7.2.0–7.2.6 and 7.0.0–7.0.5.
- Fixed versions: FortiOS 7.6.4, 7.4.9, 7.2.12 or 7.0.18 (or later), and FortiSwitchManager 7.2.7 or 7.0.6 (or later). The 6.4 branch has no fix.
- Severity: Fortinet gives it a CVSS score of 7.4 and notes that the system's memory protections make exploitation more complex. Not impossible: CISA considers it exploited.
- Known scope: according to SOCRadar, cited by SecurityWeek, 178 devices have been infected with PivotC2 in attacks aimed mainly at US entities, with at least two intrusions that ended in data theft. SOCRadar attributes the attacks to a Russian-speaking cybercriminal group and believes PivotC2 was probably developed with the help of AI.
What we don't know yet
- How many devices were attacked. SecurityWeek mentions "more than 30,000" IP addresses targeted; other coverage of the same report gives a figure ten times lower. We haven't been able to consult SOCRadar's original report, so we don't treat either figure as confirmed.
- Whether there are victims in Spain. None have been confirmed.
- Fortinet's advisory, in the version we consulted, doesn't yet flag the vulnerability as exploited, although CISA does.
Why it matters
The firewall is the front door to a company's network. An attacker who controls the firewall doesn't need to trick anyone with an email: they're already inside, at the point where all the traffic flows.
And there's a detail that repeats itself in almost every attack of this kind: the fix had existed for months. The problem isn't that there was no patch, but that many devices were never updated.
What it means for an SME
FortiGate is one of the most common firewalls in small and medium-sized businesses, and it usually arrives through the IT provider. In practice, that means that in many SMEs:
- nobody in the company knows which version of FortiOS the firewall runs;
- it isn't clear who is responsible for updating it;
- the device may have been running for years "without any problems", which is exactly what makes it invisible.
None of this takes technical knowledge to solve. It takes asking the right questions.
What your company should do this week
- Ask your IT provider whether you have FortiGate or FortiSwitchManager and which version they run. If it isn't one of the fixed versions, ask for the update.
- If the answer is "FortiOS 6.4", there's no patch: ask for a plan to migrate to a supported version.
- If you can't update straight away, Fortinet describes a temporary workaround your provider will know how to apply: remove "fabric" access from the interfaces or block ports 5246 to 5249 with a local-in policy.
- Ask them to check for signs of intrusion. The flaw has been exploited since July: updating now closes the door, but it doesn't remove anyone who already got in.
- Put in writing who is responsible for updating the firewall and how often. If nobody has been assigned the task, nobody does it.
If you're not sure which of your company's devices are exposed to the internet, start there: that's exactly what a cybersecurity audit reviews.
Sources
- Fortinet PSIRT — advisory FG-IR-25-084 (CVE-2025-25249), published 13 January 2026 and updated 23 February 2026Primary source
- CISA — four vulnerabilities added to the KEV catalogue (9 September 2026)Primary source
- SecurityWeek — «Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks» (Ionut Arghire, 10 September 2026)
Defentria editorial team. The Defentria team selects cybersecurity news from primary sources (CERTs, official bodies and vendors) and explains what it means for a Spanish SME and what to do about it.