← Back to Feed

Fortinet Products Remote Code Execution Vulnerability

CVE-2025-25249

October 2, 2026 · HKCERT · Severity: HIGH

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and data manipulation on the targeted system.   Note: CVE-2025-25249 is being exploited in the wild. An Improper Limitation of a Pathname... Impact Remote Code Execution Data Manipulation System / Technologies affected FortiMail FortiMail 8.0.0 through 8.0.1 FortiMail 7.6.0 through 7.6.6 FortiMail 7.4.0 through 7.4.8 FortiMail 7.2.0 through 7.2.9 Solutions Before installation of the software, please visit the vendor web-site for more details.   Apply fixes issued by the vendor: https://fortiguard.fortinet.com/psirt/FG-IR-26-175

☕ Buy a Coffee