CVE-2025-25249Active Exploitation(fortinet / fortios)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 18 mentions and remains active

Immediate actions

  • Patch fortinet fortios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

9.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-12. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-122CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios
  • fortisase
  • fortiswitchmanager
  • ruggedcom_ape1808

Threat summary

  • Active exploitation appears in 51 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 62 mentions across 13 observed days

What's happening

  • Active exploitation reported across 51 signals
  • Exploit tool or code specified in 13 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 30 signals
  • Technical details provided in 29 signals
  • Peaked 8d ago at 18 mentions (2026-09-10); latest day: 2
  • 62 total mentions across 13 days

Affected systems

Products
fortiosfortisasefortiswitchmanagerruggedcom_ape1808ruggedcom_ape1808_firmware

3 versions affected across 5 products

Deep dive

Activity timeline62 mentions / 13d
0591418Mentions · 2026-03-15: 1Mentions · 2026-05-21: 1Mentions · 2026-09-08: 5Mentions · 2026-09-09: 8Mentions · 2026-09-10: 18Mentions · 2026-09-11: 10Mentions · 2026-09-12: 4Mentions · 2026-09-13: 2Mentions · 2026-09-14: 8Mentions · 2026-09-17: 1Mentions · 2026-09-20: 1Mentions · 2026-09-24: 1Mentions · 2026-09-25: 2PoC Mentioned / Linked · 2026-09-08: 1PoC Mentioned / Linked · 2026-09-09: 3PoC Mentioned / Linked · 2026-09-10: 1PoC Mentioned / Linked · 2026-09-11: 2PoC Mentioned / Linked · 2026-09-13: 1PoC Mentioned / Linked · 2026-09-14: 1Exploit Tool / Code · 2026-09-08: 1Exploit Tool / Code · 2026-09-09: 4Exploit Tool / Code · 2026-09-11: 1Exploit Tool / Code · 2026-09-12: 2Exploit Tool / Code · 2026-09-13: 1Exploit Tool / Code · 2026-09-14: 4Active Exploitation · 2026-09-08: 4Active Exploitation · 2026-09-09: 7Active Exploitation · 2026-09-10: 14Active Exploitation · 2026-09-11: 10Active Exploitation · 2026-09-12: 3Active Exploitation · 2026-09-13: 2Active Exploitation · 2026-09-14: 7Active Exploitation · 2026-09-17: 1Active Exploitation · 2026-09-20: 1Active Exploitation · 2026-09-24: 1Active Exploitation · 2026-09-25: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-09-08: 1Patch / Workaround · 2026-09-09: 1Patch / Workaround · 2026-09-10: 12Patch / Workaround · 2026-09-11: 5Patch / Workaround · 2026-09-12: 2Patch / Workaround · 2026-09-13: 2Patch / Workaround · 2026-09-14: 2Patch / Workaround · 2026-09-17: 1Patch / Workaround · 2026-09-20: 1Patch / Workaround · 2026-09-24: 1Patch / Workaround · 2026-09-25: 1Technical Details · 2026-03-15: 1Technical Details · 2026-09-08: 1Technical Details · 2026-09-09: 4Technical Details · 2026-09-10: 10Technical Details · 2026-09-11: 5Technical Details · 2026-09-12: 2Technical Details · 2026-09-13: 2Technical Details · 2026-09-14: 1Technical Details · 2026-09-17: 1Technical Details · 2026-09-20: 1Technical Details · 2026-09-25: 103-1505-2109-0809-0909-1009-1109-1209-1309-1409-1709-2009-2409-25
Signal classification5 categories
Active Exploitation
4674.2%
Patch
711.3%
Exploit
46.5%
Disclosure
34.8%
General
23.2%
Referenced assets60 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-151
Patch1
2026-05-211
General1
2026-09-085
Active Exploitation4Disclosure1
2026-09-098
Active Exploitation6Exploit2
2026-09-1018
Active Exploitation11Disclosure1Patch6
2026-09-1110
Active Exploitation10
2026-09-124
Active Exploitation2Exploit1General1
2026-09-132
Active Exploitation2
2026-09-148
Active Exploitation7Exploit1
2026-09-171
Active Exploitation1
2026-09-201
Active Exploitation1
2026-09-241
Active Exploitation1
2026-09-252
Active Exploitation1Disclosure1
Full discourse20 posts
  • SOCRadar®@socradar
    Active Exploitation

    🚨 SECURITY ALERT: Active exploitation of FortiGate firewalls is underway! Attackers are targeting CVE-2025-25249 to deploy PivotC2—a custom Node.js RAT built specifically for post-exploitation on FortiGate appliances. Over 30,000 IPs targeted so far. Here's what you need to know 🧵👇 #CyberSecurity #FortiGate #ThreatIntel

    Post summary

    The post reports active exploitation of FortiGate firewalls via CVE-2025-25249, with attackers using the PivotC2 RAT and affecting more than 30,000 IPs.

    993549829060.3K
    7.1K followersView on X
  • Faruk Sener@SansLimit3
    Active Exploitation

    🚨 Our team analyzed a campaign exploiting CVE-2025-25249 to compromise #FortiGate devices and deploy #PivotC2, a Node.js RAT built for post-exploitation. 30K+ targeted IPs and identified 178 compromised devices, alongside the infrastructure and tooling used throughout the campaign. Full research: https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/

    Post summary

    The tweet reports a real‑world exploitation campaign targeting FortiGate devices via CVE‑2025‑25249, with 178 confirmed compromises and evidence of attacker infrastructure.

    015129235.7K
    970 followersView on X
  • FOFA@fofabot
    Active Exploitation

    ⚠️⚠️ CVE-2025-25249 (CVSS 9.8): Heap-based buffer overflow in FortiOS cw_acd (CAPWAP UDP/5246) → unauthenticated RCE. Previously disclosed, now actively exploited to deploy the PivotC2 RAT on internet-facing FortiGate firewalls (178+ devices infected). 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJGT1JUSU5FVC1GaXJld2FsbCI= 🎯3.6M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="FORTINET-Firewall" 🔖Refer: https://threataft.com/articles/fortinet-cve-2025-25249-pivotc2-rat #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    CVE‑2025‑25249 is a heap‑based buffer overflow in FortiOS that is currently being exploited in the wild to deploy the PivotC2 RAT across FortiGate firewalls, affecting over 178 devices.

    011119123.6K
    14.8K followersView on X
  • Lontz@lontze7
    Active Exploitation

    Active exploitation of CVE-2025-25249 is dropping #PivotC2, an AI-assisted Node.js RAT tailored for FortiGate post-exploitation. - SOCKS5 tunneling, CIDR scanning, config harvesting and credential decryption - 30k+ IPs targeted / 178 confirmed infections 🔗https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/ https://t.co/Gu7n3TVg1S

    Post summary

    The post confirms that CVE-2025-25249 is currently being exploited in the wild, with an AI-assisted Node.js RAT (#PivotC2) deployed to over 30,000 targeted IPs and 178 confirmed infections.

    0701431.7K
    1.4K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    Active Exploitation

    🚨 CISA ADDS FORTINET CVE-2025-25249 TO KEV CISA has added CVE-2025-25249 (Fortinet FortiOS / FortiSwitchManager heap-based buffer overflow in the cw_acd daemon) to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation (added 2026-09-09; federal remediation deadline noted as 2026-09-12). Per CISA / Fortinet PSIRT (FG-IR-25-084): • Unauthenticated remote code execution risk via crafted packets to affected FortiOS / FortiSwitchManager builds • Fixed builds include FortiOS 7.6.4+, 7.4.9+, 7.2.12+, 7.0.18+ and FortiSwitchManager 7.2.7+ / 7.0.6+ (see advisory for full matrix) • Organizations should prioritize patching and review exposure of CAPWAP-related services ⚠️ Analyst Note: KEV listing establishes evidence of exploitation in the wild, not that every internet-facing FortiOS instance is compromised. Validate inventory, apply vendor fixes, and follow CISA BOD guidance where applicable. Official sources: https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog https://fortiguard.fortinet.com/psirt/FG-IR-25-084 #CyberSecurity #Fortinet #CVE #CISA #KEV #ThreatIntel #DDW #DarkWeb

    Post summary

    CISA has added CVE-2025-25249 to its KEV Catalog due to evidence of active exploitation in the wild, while Fortinet has disclosed specific patched versions to mitigate the heap-based buffer overflow in FortiOS/FortiSwitchManager.

    2001366.9K
    206.9K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2025-25249 (Fortinet複数製品) - CVE-2026-19490 (Citrix Netscaler) - CVE-2026-87491 (Chromium) - CVE-2026-20079 (Cisco FMC) https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog

    Post summary

    CISA has added four CVEs to its catalog of known exploited vulnerabilities, confirming active exploitation in the wild.

    1101441.3K
    7.8K followersView on X
  • SOCRadar®@socradar
    Disclosure

    🔍 What is CVE-2025-25249? It's a critical heap-based buffer overflow in FortiOS / FortiSwitchManager (cw_acd daemon listening on UDP 5246 CAPWAP port). Unauthenticated attackers exploit it to achieve Remote Code Execution (RCE) and spawn an outbound Node.js reverse shell. #CVE202525249 #RCE #CAPWAP

    Post summary

    Critical heap-based buffer overflow in FortiOS/FortiSwitchManager’s cw_acd daemon on the CAPWAP UDP 5246 port allows unauthenticated RCE via a Node.js reverse shell.

    100634.5K
    7.1K followersView on X
  • Group-IB Global@GroupIB
    Active Exploitation

    Fortinet CVE-2025-25249 is being used to drop PivotC2 RAT. Hits FortiOS, FortiSwitchManager, FortiSASE. 3,000+ IPs targeted, 178 devices infected, mostly US. The annoying part? These are firewalls and gateways. The stuff you buy to keep attackers out is the way in. Patch and hunt. #infosec

    Post summary

    The tweet reports that CVE-2025-25249 is actively exploited in the wild, dropping the PivotC2 RAT on FortiOS, FortiSwitchManager, and FortiSASE, and urges immediate patching.

    21050350
    10.0K followersView on X
  • Mert SARICA@MertSARICA
    Active Exploitation

    🚨 New research from the SOCRadar Threat Research Unit! CVE-2025-25249 is being actively exploited to deploy PivotC2, a FortiGate-focused Node.js RAT. 30K+ targets. 178 confirmed infections. AI-assisted development, tunneling & autonomous post-exploitation. Read more 👇 https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/

    Post summary

    CVE-2025-25249 is reported as actively exploited, with 30,000+ targets and 178 confirmed infections using the PivotC2 RAT on FortiGate devices.

    00042481
    7.4K followersView on X
  • YourDailyCVE@YourDailyCVE
    Active Exploitation

    🚨 CVE-2025-25249 — Fortinet FortiOS & FortiSwitchManager, heap overflow to full device takeover; CVSS 9.8 What broke: FortiGate firewalls run a background service called cw_acd, which listens on a network port to manage groups of Fortinet devices (part of Fortinet's "fabric" system for centrally controlling firewalls and switches). That service didn't properly check the size of incoming data before copying it into memory — a classic "heap-based buffer overflow." Send it a deliberately oversized, malformed packet, and it overflows into memory it shouldn't touch, letting an attacker run their own code instead. Who should care: anyone running FortiOS 6.4–7.6 (specific ranges below current patched versions) or FortiSwitchManager 7.0–7.2. This affects the firewall appliance itself, not a downstream service. Impact: this is unauthenticated remote code execution — no credentials, no user interaction, just network access — on the device sitting at the edge of your network, watching all your traffic. Researchers at SOCRadar found attackers using it to install PivotC2, a custom-built remote access trojan that gives them an interactive shell, network scanning, and tunneling capability inside the compromised network — not just a one-time break-in, but a foothold for continued access. They've confirmed 178 compromised devices and two full network intrusions with data theft, out of a target list of over 30,000 internet-facing FortiGate IPs still running unpatched firmware. Status: actively exploited. Fortinet patched this back in January 2026, but real-world exploitation wasn't confirmed until July — eight months later — and CISA only added it to KEV on Sept 9, with a federal deadline of Sept 12 (today). The attackers are assessed to be a financially motivated, Russian-speaking cybercrime group, not a nation-state actor. Fix today: upgrade to FortiOS 7.6.4, 7.4.9, 7.2.12, or 7.0.18, or the fixed FortiSwitchManager build for your branch. If you can't patch: disable the fabric/CAPWAP service on internet-facing interfaces, or block inbound UDP traffic on ports 5246–5249 at your perimeter. Also worth checking your FortiGate estate for the file /tmp/.i.js, a known indicator of compromise from this campaign. Source: Fortinet PSIRT (FG-IR-25-084) / SOCRadar / CISA KEV #Fortinet #FortiGate

    Post summary

    The post reports widespread, real‑world exploitation of CVE-2025-25249, including compromise counts, patch details, and mitigation recommendations.

    10021253
    35 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Exploit

    Discover how the PivotC2 FortiGate RAT uses CVE-2025-25249 exploitation to harvest credentials and tunnel traffic across corporate network environments. #PivotC2 #FortiGate #Malware #Cybercrime #CVE202525249 https://securityonline.info/pivotc2-fortigate-rat/

    Post summary

    The text discloses the PivotC2 FortiGate RAT as a named attack tool leveraging CVE-2025-25249 for credential harvesting and network traffic tunneling, linking to an external article for further details.

    02010449
    13.0K followersView on X
  • Anurag Verma@anurag_629
    Active Exploitation

    A FortiOS bug has been quietly exploited since July, and 178 networks already have a backdoor because of it. CVE-2025-25249 is an unauthenticated heap overflow in FortiOS, FortiSwitchManager and FortiSASE. Attackers used it to drop a Node.js RAT called PivotC2 across more than 3,000 targeted IPs, confirmed by @Fortinet and covered here: https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html CISA added it to the KEV catalog this week. Federal agencies had until September 12 to patch. That deadline already passed. If you run FortiOS anywhere, check your version today, not after the next scan report.

    Post summary

    CVE‑2025‑25249, an unauthenticated heap overflow in FortiOS, has been actively exploited since July, with attackers deploying the PivotC2 RAT on thousands of IPs; the vulnerability has been added to CISA’s KEV catalog with a passed patch deadline.

    00021138
    312 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2025-25249 actively exploited since July 2026: Russian-speaking crew drops PivotC2, a Node.js RAT purpose-built for FortiGate post-exploitation, hitting 178 confirmed devices from a 30,000-IP target list. - CVE-2025-25249 (CVSS 9.8) is a heap-based buffer overflow in the FortiOS/FortiSwitchManager cw_acd daemon, reachable unauthenticated over UDP 5246. The exploit binary fortirun.bin (SHA256: 2d338f...) fingerprints firmware via CAPWAP discovery, leaks live memory pointers to defeat ASLR, groans the heap with crafted Add Station messages, then corrupts a doubly-linked free list to gain write-what-where and pivot execution into Node.js, which ships natively with FortiOS, no dropper needed. - PivotC2 (v0.2.3, AI-assisted) lands at /tmp/.i.js after a Base64+XOR (key: pivot) stager fetches it from hxxps://146.103.99[.]177:8443/0c5b76709523. It beacons out over a single TLS socket, multiplexing shells, file ops, SOCKS5/HTTP tunneling, port forwarding, and CIDR scanning. Auto-mode autonomously harvests /data/config/sys_global.conf.gz, /data/config/sys_vd_root+root.conf.gz, and /data/etc/fsv_sync.dat, then decrypts ENC credentials (AES-256-CBC or AES-128-GCM) yielding VPN PSKs, SSL-VPN creds, LDAP bind secrets, and admin accounts. #DFIR_Radar

    Post summary

    The passage reports active exploitation of CVE-2025-25249 with detailed technical exploitation steps, a distributed RAT, and confirmed device infections, highlighting an ongoing in‑the‑wild attack scenario.

    10110287
    1.9K followersView on X
  • kotaro@サイバーセキュリティ情報発信@ngsk_ciso
    Active Exploitation

    Fortinetが、FortiOS/FortiSwitchManagerの無線AP管理まわり(cw_acd)にヒープバッファオーバーフロー(CVE-2025-25249、CVSS 7.4)があると公表している。遠隔の未認証攻撃者が、細工したリクエストで不正なコードやコマンドを実行できる恐れがある。直す版は FortiOS 7.6.4以上/7.4.9以上/7.2.12以上/7.0.18以上。FortiOS 6.4系は現行PSIRTでは固定リリースへ移行。FortiSwitchManagerは7.2.7以上/7.0.6以上。公式PSIRTの「Known Exploited」欄は本稿時点でNoのまま(最終更新2026-02-23)。一方、米CISAは2026年9月9日にKnown Exploited Vulnerabilities(既知の悪用済み脆弱性カタログ)へ本CVEを追加した。 普通の会社だと、長崎の製造・建設でも支店や工場の入口にFortiGateを置く会社は多い。CAPWAP(無線AP管理)やfabricがインターネット側に届く設定だと、ファイアウォール自体が踏み台になり、VPNや社内設定の認証情報まで持っていかれる話につながる。修正版は年初から出ているのに、KEV入りで「まだ直していない箱」が狙い目になっている。 今見るのは、①全FortiGate/FortiSwitchManagerの現行版を台帳で抜き、影響版が残っていないか確認。②未更新なら上記直す版へ上げる(6.4系はサポート対象へ移行)。③fabric/CAPWAPがインターネット側に開いていないか確認し、不要なら閉じる(公式の回避策)。④過去に脆弱版で外向きに届いていた機器は、パッチ済み=無事とせず、不審な外向き通信や設定変更の有無を見る。疑わしい場合は管理者パスワード・SSL-VPN・LDAP/PSK等のローテーションを検討。 https://fortiguard.fortinet.com/psirt/FG-IR-25-084

    Post summary

    Japanese advisory reports CVE-2025-25249 heap buffer overflow in Fortinet products, highlights CISA KEV addition as evidence of active exploitation, and provides patch versions plus mitigation steps.

    10010165
    33 followersView on X
  • CyberSignal | Cybersecurity & AI News@XQOPTRX
    Active Exploitation

    🚨 CYBER DEADLINE TODAY: CISA’s remediation clock expires for CVE-2025-25249. The actively exploited Fortinet heap-overflow flaw affects FortiOS, FortiSwitchManager and FortiSASE and can let a remote attacker execute unauthorized code via crafted packets. CISA added it to KEV on Sept. 9 and requires federal agencies to remediate it by Sept. 12. Researchers have also observed attackers deploying PivotC2 after exploitation. Patch exposed Fortinet systems now.

    Post summary

    CVE‑2025‑25249, a heap‑overflow flaw in Fortinet devices, is actively exploited in the wild with attackers using PivotC2, prompting CISA to place it on KEV and require immediate remediation while patches are now available.

    0101078
    215 followersView on X
  • YourDailyCVE@YourDailyCVE
    General

    Source https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/

    Post summary

    The provided input contains only a URL reference without any substantive information about the CVE.

    0001198
    29 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Active Exploitation

    "Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability: Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially…" https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-25249

    Post summary

    The statement describes a heap‑based buffer overflow in Fortinet products (CVE‑2025‑25249) and references the CISA catalog, indicating that the flaw is being actively exploited, though no exploit code or mitigation detail is provided.

    10001319
    3.5K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Active Exploitation

    CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/ "The SOCRadar Threat Research Unit (STRU) identified, with high confidence, exploitation of CVE-2025-25249, a heap-based buffer overflow vulnerability in FortiOS and…"

    Post summary

    CVE‑2025‑25249, a heap‑based buffer overflow in FortiOS, has been actively exploited, delivering the PivotC2 post‑exploitation RAT.

    10010401
    3.5K followersView on X
  • 서버쟁이 놀이터@ueo0j
    Patch

    📊 9/10 통합 브리핑 KEV가 이틀 연속 8건이다. 오늘 1순위는 Cisco FMC(CVE-2026-20079, CVSS 10.0)—Sandworm 연계·Qilin까지 실제 침해. 패치보다 침해 조사가 먼저고, CISA 기한은 모레(09-12). —— 오늘 먼저 —— ① Cisco Secure FMC — 핫픽스 + 침해 조사 먼저 CVE-2026-20079 미인증 root(CVSS 10.0). Talos가 UAT-11823(Sandworm)·UAT-11988(Qilin) 등 3개 클러스터 확인. 웹셸·JAR 실행기·잔존 세션·터널 흔적부터. Snort SID 66075–66080·66883·66960–66961. 기한 09-12. ② Citrix NetScaler · Fortinet — KEV 등재, 기한 09-12 CVE-2026-19490(Gateway·AAA) / CVE-2025-25249(FortiOS 등). PoC 이후 악용 관측→KEV. 미패치면 원격 접속 관문이 열린 상태. 구형 FortiOS 자산 우선 확인. ③ Adobe Commerce / Magento StyleSmuggler — 조사 후 핫픽스+키 전면 교체 CVE-2026-75650 미인증 RCE, Adobe가 "악용 중" 공식 확인. 기한 09-11. VULN-39341 적용 후 암호화 키·관리자·API·결제·DB·SSH 전부 로테이션. ④ Chrome 153.0.8010.36/.37 강제 업데이트 CVE-2026-87491 V8 OOB write, 5일 만의 두 번째 악용 제로데이. 152.x는 아직 취약. 전 임직원 단말 즉시. 발견: 서울대 Compsec Lab 정지현. ⑤ EU CRA 보고 의무 — 내일(09-11) 발효 D-1 악용 취약점·중대 사고 24h/72h 보고. ENISA SRP 한 번 제출로 전달. 오늘 안: 대상 제품 식별·보고 책임자·SRP 계정. "인지" 판정자도 먼저 정의. —— AI —— ──────── ▣ OpenAI, 나비에–스토크스 밀레니엄 문제 해결 주장 — 검증·공로 분쟁 진행 중 핵심: ~1만 에이전트 88시간·Lean 형식화. $100만 상금 미청구. Buckmaster 크레딧 문제·Córdoba 등 선행 기여 지적. 동료평가 미완. 왜 중요한가: Lean 통과는 "검증 가능 AI 증명"의 실증. "AI가 풀었다" 프레이밍은 아직 기업 의사결정 근거로 쓰기 이름—검증 상태를 함께 명시. https://openai.com/index/navier-stokes-solution/ ──────── ▣ Anthropic, 네 번째 사이버보안 사고 공개 — 에이전트 egress 통제 체크리스트 핵심: Opus 4.6 초기 버전 테스트 중 인터넷 접근 오부여(1월 발생, 사후 재검토로 발견). 당사자 통지·METR 제3자 검토 협의. 7월 3건과 별개. 왜 중요한가: 실시간 탐지가 아니라 8개월 뒤 사후 감사로 잡힘. egress 기본 차단·샌드박스·세션 전수 로그·트랜스크립트 보존이 사내 에이전트 운영 항목. https://www.reuters.com/legal/litigation/anthropic-reports-fourth-cybersecurity-incident-with-early-version-claude-2026-09-09/ ──────── ▣ Google·Anthropic·OpenAI, 사이버보안 특화 모델 동시 출시 핵심: Gemini 3.8 Flash Cyber(Fairwind)·Claude Fable/Mythos 5.1·OpenAI Astra(Daybreak Blue). 방어 접근을 심사된 조직 우선 배분. 왜 중요한가: 중견은 공격 자동화 타격은 즉시, 방어 자동화는 늦게. Unit 42의 "AI 병렬 침해 10시간" 실증과 같은 주—구조적 비대칭. https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html ──────── ▣ Meta Muse 개인 AI 에이전트 정식 출시 핵심: 메일·일정·쇼핑·예약·결제 연동. Workspace·Ticketmaster·OpenTable·Stripe. 무료+$20+$100/월. 왜 중요한가: 소비자 에이전트가 회사 계정·결제에 붙는 분기점. Workspace 연결 허용·프롬프트 인젝션 책임·EU AI Act 투명성 의무를 정책으로 먼저 잡아라. https://techcrunch.com/2026/09/08/meta-debuts-its-muse-ai-agent-will-consumers-trust-it/ ──────── ▣ OpenAI GPT-6 Astra, Amazon Bedrock GA 핵심: 100만 토큰 컨텍스트·심층 추론. Bedrock에서 GA(09-10). 왜 중요한가: 엔터프라이즈 조달 경로가 클라우드 콘솔로 바로 열린다. 장문 RAG·에이전트 파이프라인 단가·가드레일 재점검 계기. https://aws.amazon.com/about-aws/whats-new/2026/09/openai-gpt-6-astra-on-amazon-bedrock/ ──────── ▣ DeepMind AlphaGenome Atlas — 인간 유전체 변이 영향 예측 지도 핵심: ~90억 단일염기변이 분자 영향 예측, ~1PB. AVI 지표·웹/API/Antigravity. 비상업 학술 무료, 상업은 Google Cloud 경유. 왜 중요한가: 변이 해석이 "모델 실행"에서 "인덱스 조회"로. 게놈 파이프라인의 클라우드 종속 논의가 따라온다. https://deepmind.google/blog/alphagenome-atlas-a-predictive-map-of-every-possible-dna-letter-change-in-the-human-genome/ —— 클라우드·데이터센터·인프라 —— ──────── ▣ Google 핀란드 €130억 + Fortum 22년 원전 PPA 핵심: 향후 2년 €130억 디지털 인프라(신규 DC 포함). Loviisa 원전 출력 50%를 2030–2049 확보—Fortum €10억 수명연장의 매출 확실성. 왜 중요한가: REC가 아니라 24/7 무탄소 기저부하 20년. 하이퍼스케일러가 발전 자산 자본 구조에 개입하는 선례—국내 DC 전력 계약에도 적용. https://blog.google/innovation-and-ai/infrastructure-and-cloud/global-network/google-ai-commitment-to-finland/ ──────── ▣ Qualcomm–AWS 커스텀 추론 실리콘 — $600억은 오독 핵심: 공식 보도자료에 금액 없음. 다세대 추론 칩·최대 1.6T 광연결·EDA를 Bedrock 등으로 이전. $600억은 워런트 베스팅 산정 상한(CNBC 등), 매출 확약 아님. 왜 중요한가: 추론이 학습보다 큰 지출이 된 시점의 Nvidia 의존 분산. 워런트 구조는 단기 공급이 아니라 장기 종속 설계에 가깝다. https://www.qualcomm.com/news/releases/2026/09/qualcomm-announces-multi-generational-product-collaboration-with ──────── ▣ NextEra Duane Arnold 재가동 DOE $19억 vs 오리건 공유지 DC 동결 핵심: 아이오와 615MW 원전 재가동 대출+Google 25년 PPA(2029). 오리건은 주지사가 공유지 DC 거래 2027-07-01까지 중단. 왜 중요한가: 연방은 전력 늘리고 주는 토지를 잠근다. AI 인프라 병목이 GPU→전력→지방 정치·물·토지로 이동. https://www.datacenterdynamics.com/en/news/nextera-secures-19bn-loan-from-us-doe-to-support-restart-of-the-duane-arnold-nuclear-power-plant-in-linn-county-iowa/ ──────── ▣ OpenAI–삼성, 차세대 칩 공동 연구·생산 시사 핵심: OpenAI 코리아 총괄이 "가장 진전 큰 영역은 차세대 칩 공동 생산·연구" 발언. 사양·일정 비공개, 삼성은 확인 거부. Stargate 메모리 MOU에 이은 신호. 왜 중요한가: Jalapeño(Broadcom+TSMC) 추론 칩 전략이 메모리 공급을 넘어 설계·생산 협력으로. 국내 반도체 밸류체인 후속 확인 가치. https://www.bnnbloomberg.ca/business/artificial-intelligence/2026/09/09/openai-says-working-with-samsung-on-next-generation-chips-deepening-cooperation/ ──────── ▣ AWS Lambda Graviton5 + 타임아웃 90분 핵심: Graviton4 대비 ~25% 성능. 비동기/ESM 호출 제한 15분→90분. API Gateway 백엔드 mTLS·Bedrock KB Confluence DC 커넥터도 동시. 왜 중요한가: 배치·AI 추론을 Step Functions로 쪼개지 않고 Lambda에 둘 여지. 아키텍처 단순화 포인트. https://aws.amazon.com/about-aws/whats-new/2026/09/aws-lambda-graviton5-ec2/ —— 보안·규제 —— ──────── ▣ EU 사이버복원력법(CRA) 보고 의무 — 내일(09-11) 발효 핵심: 조기경보 24h·정식 72h·악용 취약점 최종 14일·중대사고 1개월. ENISA SRP 단일 제출. 오픈소스 스튜어드도 대상. 왜 중요한가: "악용 중 공개"가 EU 시장 진입 조건이 된다. 준비 여부와 무관하게 시한이 시작—오늘 안에 식별·책임자·계정. https://digital-strategy.ec.europa.eu/en/policies/cra-reporting ──────── ▣ Microsoft, 패스키 테마 SE → 클라우드 정체성 침해 핵심: 패스키 도입을 미끼로 MFA 지속성 확보 후 Graph로 SharePoint·OneDrive·메일 접근. BigBear 2.0(AiTM PhaaS)과 같은 계열—M365 수천 계정 탈취 사례. 왜 중요한가: "MFA·패스키 켰다"≠방어 완료. 세션·Graph 앱 권한이 새 공격면. CA·FIDO2 강제·세션 무효화·http://Mail.Read/Files.Read.All급 앱 전수 점검. https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ ──────── ▣ ENISA 새 전략 — EU 사이버 정책 운영 허브화 핵심: 위협 예측·공동 지식·정책 이행·위기 대비·역량 강화 등 7개 목표. NIS2·CRA와 맞물림. 왜 중요한가: 보고·규제 이행의 실무 창구가 ENISA로 모인다. EU 공급 라인은 SRP·전략 문서부터 읽어둘 것. https://www.enisa.europa.eu/press-office/press-and-media/a-trusted-and-cyber-secure-europe-enisa-strategy —— 취약점·해킹 —— ──────── ▣ 🔴 CVE-2026-20079 Cisco Secure FMC — CVSS 10.0, 오늘의 최우선 핵심: 부팅 잔존 csm_processes 세션 승격→미인증 root. Talos 확인 침해: 웹셸·설정 전수 수집·Cyclops Blink·AD 수확·랜섬웨어. CVE-2026-20316(정적 자격증명) 병행. 왜 중요한가: 방화벽이 아니라 관리 평면이 넘어가면 정책·자격증명·AD가 한꺼번에. 국가 첩보와 랜섬웨어가 같은 취약점을 동시에 씀. 패치보다 침해 조사 먼저. 기한 09-12. https://blog.talosintelligence.com/fmc-ongoing-exploitation/ ──────── ▣ CISA KEV 이틀 연속 8건 — 09-09 배치를 원본 4개가 놓침 핵심: 09-08 MS제로데이2·Adobe·N-able / 09-09 Cisco·Citrix·Fortinet·Chrome. 통합 재검증 없으면 CVSS10 FMC가 통째로 빠질 뻔. 왜 중요한가: Patch Tuesday 주간은 뉴스 사이클에 갇히지 말고 KEV 카탈로그를 직접 조회하라. https://www.cisa.gov/news-events/alerts/2026/09/09/cisa-adds-four-known-exploited-vulnerabilities-catalog ──────── ▣ Microsoft 9월 패치 — 역대급 규모, 제로데이 2 + DNS RCE 우선 검토 핵심: CVE-2026-81963(Update Stack)·85880(ALPC) 실제 악용→SYSTEM. 외부 노출 DNS면 CVE-2026-69730(CVSS 9.8 미인증 RCE)을 제로데이보다 높게. 매체별 총건수 964–974 충돌. 왜 중요한가: AD 통합 DNS=DC 위 코드 실행 경로. 900건대는 일괄 배포가 아니라 링 검증·플레이북 문제. https://msrc.microsoft.com/update-guide/en-us/releaseNote/2026-sep ──────── ▣ Adobe Commerce StyleSmuggler (CVE-2026-75650) — 패치만으로 안 끝 핵심: 미인증 RCE, 영향 2.4.4–2.4.9(공식). NTP 위장 백도어·485B PHP 웹셸. 핫픽스 VULN-39341 + 결제 게이트웨이 포함 자격증명 전면 교체. 왜 중요한가: Adobe가 키 교체를 공식 권고한 건 패치 전 침해 가능성을 전제. 커머스 스택은 조사→패치→로테이션 순. https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/announcements/commerce-apsb26-146 ──────── ▣ Chrome V8 제로데이 CVE-2026-87491 — 5일 만 두 번째 핵심: OOB write, 샌드박스 내 코드 실행. Stable 153.0.8010.36/.37(보안 수정 230건). 서울대 정지현 발견. 09-04 CVE-2026-85046과 별개—152.x는 미해결. 왜 중요한가: 2026년 7번째 악용 Chrome 제로데이. 버전 확인이 전부다. https://www.helpnetsecurity.com/2026/09/09/google-chrome-cve-2026-87491-zero-day-flaw/ ──────── ▣ Citrix NetScaler CVE-2026-19490 — PoC 후 악용→KEV 핵심: Gateway/AAA만 해당, CVSS 9.3. Citrix 업데이트 08-19. 09-03부터 악용 시도 관측, 09-09 KEV, 기한 09-12. 왜 중요한가: 8월 패치했으면 이미 안전. 미적용이면 원격 접속 관문이 열려 있음—오늘 확인. https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/ ──────── ▣ SAP 9월 패치 — CVSS 10.0 OVERPASS (EPP) 핵심: 노트 22건. #3747649 Extended Passport 메모리 손상 CVSS 10.0(KERNEL·Web Dispatcher). Message Server 인증 누락 CVSS 9.8 등. 악용 보고 없음. 왜 중요한가: 앱 패치가 아니라 커널 업그레이드—정지 창 확보가 대응 속도. 악용 없다고 미루면 창 실패로 수주 밀림. https://onapsis.com/blog/sap-security-patch-day-september-2026/ —— 개발자·엔터프라이즈 —— ──────── ▣ GitHub, 노출 secret 있으면 PR merge 차단 + 에이전틱 autofix 핵심: ruleset `Require secret scanning alerts are resolved`—미해소 alert면 merge 차단(Secret Protection/Advanced Security, public preview). Code Quality findings를 Copilot에 일괄 할당해 autofix PR. 왜 중요한가: push protection 우회·지연 탐지 secret이 그대로 merge되던 구멍에 merge 게이트 추가. Actions 침투 사례와 함께 CI/CD 방어선 강화 신호. https://github.blog/changelog/2026-09-09-block-pull-requests-with-exposed-secrets-from-merging/ ──────── ▣ Kubernetes v1.37 — 워크로드 인지 스케줄링(WAS) 베타 핵심: Workload/PodGroup API·Preemption 베타. 분산 AI/ML 갱 스케줄링을 코어로. 왜 중요한가: Pod 단위 스케줄러의 "일부만 뜨고 대기" 문제 완화. Volcano·Kueue 쓰면 마이그레이션 경로 검토 시점(베타—프로덕션은 신중). https://kubernetes.io/blog/2026/09/08/kubernetes-v1-37-advancing-workload-aware-scheduling/ ──────── ▣ Accenture × Google Cloud, Gemini Enterprise Business Group 핵심: ~5만 GCP 인력 기반 + Gemini 인증 + FDE 1,000명. 산업 템플릿·도입 가속. YouTube 사례 +11%/−37%는 양사 자체 수치. 왜 중요한가: 에이전틱 AI 병목이 모델이 아니라 도입·통합 인력. SI 선정 기준이 모델 접근→운영·변화관리로 이동. https://newsroom.accenture.com/news/2026/accenture-and-google-cloud-deepen-partnership-with-formation-of-new-accenture-gemini-enterprise-business-group 패치 창은 오늘 열고, KEV는 직접 보라. 모레(09-12)가 여러 건의 마감이다. #IT브리핑 #CISA #KEV #CiscoFMC #CVE202620079 #AdobeCommerce #Chrome제로데이 #EUCRA #PatchTuesday #AWS #GitHubSecurity #Kubernetes

    Post summary

    The briefing summarizes several CVEs, highlighting confirmed active exploitation, providing patch timelines and mitigation steps, and indicating that vendor hotfixes and updates are the principal focus.

    000201.7K
    71 followersView on X
  • ITフレブル【実務派エンジニア速報】@eng_digest_jp
    Active Exploitation

    【Fortinetを9/12までに塞げ】 ・FortiOSなどがCISA KEV入り ・細工パケットでコード実行 ・対応期限は9/12 期限つきの既知悪用、優先度が違います。 #Apple https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-25249

    Post summary

    The post highlights that FortiOS is listed in the CISA KEV catalog for CVE‑2025‑25249, indicating it is actively exploited with an imminent patch deadline of September 12.

    00020180
    5 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
Appfortinetfortisase25.1.39--
Appfortinetfortisase25.1.51--
Appfortinetfortiswitchmanager---
HWsiemensruggedcom_ape1808---
OSsiemensruggedcom_ape1808_firmware---

Explore more