CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Fortinet security advisory (AV26-023) - Update 1

criticalknown exploitedCVE-2025-25249CVE-2025-47855CVE-2025-64155
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-023 Date: January 13, 2026 Updated: September 9, 2026 On January 13, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following: FortiFone 7.0 – versions 7.0.0 to 7.0.1 FortiFone 3.0 – versions 3.0.13 to 3.0.23 FortiOS 7.6 – versions 7.6.0 to 7.6.3 FortiOS 7.4 – versions 7.4.0 to 7.4.8 FortiOS 7.2 – versions 7.2.0 to 7.2.11 FortiOS 7.0 – versions 7.0.0 to 7.0.17 FortiOS 6.4 – versions 6.4.0 to 6.4.16 FortiSASE 25.2 – version 25.2.b FortiSASE 25.1.a – version 25.1.a.2 FortiSIEM 7.4 – version 7.4.0 FortiSIEM 7.3 – versions 7.3.0 to 7.3.4 FortiSIEM 7.2 – versions 7.2.0 to 7.2.6 FortiSIEM 7.1 – versions 7.1.0 to 7.1.8 FortiSIEM 7.0 – versions 7.0.0 to 7.0.4 FortiSIEM 6.7 – versions 6.7.0 to 6.7.10 FortiSwitchManager 7.2 – versions 7.2.0 to 7.2.6 FortiSwitchManager 7.0 – versions 7.0.0 to 7.0.5 Update 1 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-25249 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Heap-based buffer overflow in cw_acd daemon – CVE-2025-25249 Unauthenticated access to local configuration – CVE-2025-47855 Unauthenticated remote command injection – CVE-2025-64155 Fortinet PSIRT Advisories CISA KEV: CVE-2025-25249

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-09-09
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-023

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-25249coverage & exploitation statusNVD · CVE.org
CVE-2025-47855coverage & exploitation statusNVD · CVE.org
CVE-2025-64155coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security