Nearly 1M FortiGate Instances Exposed Amid Actively Exploited CVE-2025-25249
A ZoomEye fingerprint scan conducted on 23 September 2026 identified 983,992 publicly indexed FortiGate instances, highlighting the scale of potential exposure to CVE-2025-25249. The vulnerability, affecting FortiOS, FortiSwitchManager, and FortiSASE, is a heap-based buffer overflow flaw that allows attackers to execute unauthorized code via specially crafted packets without prior authentication. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 9 September 2026, with the underlying vendor advisory FG-IR-25-084 assigned roughly a year earlier. Security analysts warn that with nearly a million visible instances, automated scanning can locate vulnerable hosts with minimal effort, making opportunistic exploitation highly feasible. The indexed count does not distinguish between genuinely exposed and internally isolated devices, but serves as a meaningful proxy for how rapidly attackers could identify candidate targets at scale.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in