Fortinet CVE-2025-25249 Zero-Day Added to CISA KEV Under Active Exploitation
CISA has added a critical Fortinet vulnerability, CVE-2025-25249, to its Known Exploited Vulnerabilities catalog, confirming its active exploitation in the wild.

Key findings
- Fortinet vulnerability CVE-2025-25249 confirmed actively exploited.
- Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026.
- Organizations must prioritize immediate patching of affected Fortinet products.
- Active exploitation necessitates urgent remediation to prevent compromise.
CISA has issued an urgent alert regarding Fortinet vulnerability CVE-2025-25249, which has been added to the Known Exploited Vulnerabilities (KEV) catalog due to confirmed active exploitation. This addition underscores the immediate threat posed by the flaw and the necessity for organizations to take prompt action.
CVE-2025-25249 represents a significant security risk, as threat actors are already leveraging it to compromise systems. While specific details of the vulnerability type or its impact have not been publicly disclosed beyond its KEV listing, its presence in the catalog signifies that it is being actively used in attacks, making it a high-priority concern for all Fortinet users.
The inclusion of CVE-2025-25249 in the KEV catalog means that federal civilian executive branch (FCEB) agencies are mandated to remediate this vulnerability by the specified due date, which is typically within a few weeks of its listing. However, given the active exploitation, all organizations, regardless of sector, should treat this as an immediate patching requirement.
Defenders are strongly advised to identify all Fortinet products within their environment that may be affected by CVE-2025-25249 and apply the vendor-provided security updates without delay. Proactive patching and continuous monitoring for signs of compromise are crucial steps to mitigate the risk associated with this actively exploited flaw and protect against potential breaches.