Fortinet security advisory (AV26-023) - Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial number: AV26-023 Date: January 13, 2026 Updated: September 9, 2026 On January 13, 2026, Fortinet published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following: FortiFone 7.0 – versions 7.0.0 to 7.0.1 FortiFone 3.0 – versions 3.0.13 to 3.0.23 FortiOS 7.6 – versions 7.6.0 to 7.6.3 FortiOS 7.4 – versions 7.4.0 to 7.4.8 FortiOS 7.2 – versions 7.2.0 to 7.2.11 FortiOS 7.0 – versions 7.0.0 to 7.0.17 FortiOS 6.4 – versions 6.4.0 to 6.4.16 FortiSASE 25.2 – version 25.2.b FortiSASE 25.1.a – version 25.1.a.2 FortiSIEM 7.4 – version 7.4.0 FortiSIEM 7.3 – versions 7.3.0 to 7.3.4 FortiSIEM 7.2 – versions 7.2.0 to 7.2.6 FortiSIEM 7.1 – versions 7.1.0 to 7.1.8 FortiSIEM 7.0 – versions 7.0.0 to 7.0.4 FortiSIEM 6.7 – versions 6.7.0 to 6.7.10 FortiSwitchManager 7.2 – versions 7.2.0 to 7.2.6 FortiSwitchManager 7.0 – versions 7.0.0 to 7.0.5 Update 1 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-25249 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Heap-based buffer overflow in cw_acd daemon – CVE-2025-25249 Unauthenticated access to local configuration – CVE-2025-47855 Unauthenticated remote command injection – CVE-2025-64155 Fortinet PSIRT Advisories CISA KEV: CVE-2025-25249
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-023
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2025-25249Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-478550.80% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2025-6415543.2% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 99% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-25249 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-47855 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-64155 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[UPDATE] [hoch] Fortinet FortiOS: Schwachstelle ermöglicht Codeausführungcert-bund
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerabilitycisa-kev
More from Canadian Centre for Cyber Security
- unknownFortra security advisory (AV26-906)2026-09-10
- unknownPalo Alto Networks security advisory (AV26-905)2026-09-10
- unknownAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-…2026-09-09
- unknownCitrix security advisory (AV26-833) - Update 12026-09-09
- criticalCisco security advisory (AV26-197) – Update 32026-09-09