CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0015 [1.01] [M/H] Kwetsbaarheid verholpen in Fortinet FortiOS

unknownknown exploitedCVE-2025-25249
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Fortinet heeft een kwetsbaarheid verholpen in FortiOS (Specifiek voor FortiSASE en FortiSwitchManager). De kwetsbaarheid bevindt zich in de cw_acd daemon in FortiOS en FortiSwitchManager. Deze daemon is kwetsbaar voor exploitatie door externe, niet-geauthenticeerde aanvallers. Door het verzenden van speciaal vervaardigde pakketten of verzoeken, kunnen aanvallers willekeurige code of commando's op de getroffen systemen uitvoeren. UPDATE Het Amerikaanse CISA heeft op 9 september de kwetsbaarheid op de Known Exploited Vulnerabilities-catalogus geplaatst. Organisaties wordt geadviseerd de updates van Fortinet direct toe te passen en kwetsbare, extern bereikbare systemen te controleren op aanwijzingen van misbruik. EINDE UPDATE

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-09-10
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0015

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2025-25249coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Kwetsbaarheid verholpen in

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories