CVE-2025-32756PoC(fortinet / forticamera)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch fortinet forticamera systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-04. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-121CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • forticamera
  • forticamera_firmware
  • fortimail
  • fortindr

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 11 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Peaked 10d ago at 1 mentions (2026-02-01); latest day: 1
  • 11 total mentions across 11 days

Affected systems

Vendors
Products
forticameraforticamera_firmwarefortimailfortindrfortirecorderfortivoice

10 versions affected across 6 products

Deep dive

Activity timeline11 mentions / 11d
00111Mentions · 2026-02-01: 1Mentions · 2026-02-09: 1Mentions · 2026-02-11: 1Mentions · 2026-02-22: 1Mentions · 2026-03-05: 1Mentions · 2026-03-08: 1Mentions · 2026-03-14: 1Mentions · 2026-03-22: 1Mentions · 2026-04-01: 1Mentions · 2026-04-21: 1Mentions · 2026-06-20: 1PoC Mentioned / Linked · 2026-02-01: 1PoC Mentioned / Linked · 2026-02-09: 1PoC Mentioned / Linked · 2026-02-11: 1PoC Mentioned / Linked · 2026-03-05: 1PoC Mentioned / Linked · 2026-03-08: 1PoC Mentioned / Linked · 2026-03-14: 1PoC Mentioned / Linked · 2026-03-22: 1PoC Mentioned / Linked · 2026-04-01: 1Exploit Tool / Code · 2026-03-08: 1Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-06-20: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-02-11: 1Technical Details · 2026-03-22: 1Technical Details · 2026-04-21: 1Technical Details · 2026-06-20: 102-0102-0902-1102-2203-0503-0803-1403-2204-0104-2106-20
Signal classification3 categories
PoC
872.7%
Active Exploitation
218.2%
General
19.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-011
PoC1
2026-02-091
PoC1
2026-02-111
PoC1
2026-02-221
General1
2026-03-051
PoC1
2026-03-081
PoC1
2026-03-141
PoC1
2026-03-221
PoC1
2026-04-011
PoC1
2026-04-211
Active Exploitation1
2026-06-201
Active Exploitation1
Full discourse11 posts
  • اخبار داغ امنیت شبکه - تاکیان@Takianco
    Active Exploitation

    🔴 فورتی‌نت نسبت به سوءاستفاده فعال از آسیب‌پذیری بحرانی CVE-2025-32756 در محصول FortiSandbox هشدار داد. #CyberSecurity #Fortinet #FortiSandbox #Vulnerability #ThreatIntelligence #NetworkSecurity #RCE #PatchManagement https://www.takian.ir/news/new-%D8%A2%D8%B3%DB%8C%D8%A8%E2%80%8C%D9%BE%D8%B0%DB%8C%D8%B1%DB%8C-%D8%A8%D8%AD%D8%B1%D8%A7%D9%86%DB%8C-%D8%AF%D8%B1-fortisandbox-%D9%87%D8%AF%D9%81-%D8%AD%D9%85%D9%84%D8%A7%D8%AA-%D8%B3%D8%A7%DB%8C%D8%A8%D8%B1%DB%8C-%D9%82%D8%B1%D8%A7%D8%B1-%DA%AF%D8%B1%D9%81%D8%AA%D8%9B-%D9%87%D8%B4%D8%AF%D8%A7%D8%B1-%D9%81%D9%88%D8%B1%DB%8C-%D8%A8%D9%87-%DA%A9%D8%A7%D8%B1%D8%A8%D8%B1%D8%A7%D9%86-%D9%81%D9%88%D8%B1%D8%AA%DB%8C%E2%80%8C%D9%86%D8%AA https://t.co/NczpE4GtNl

    Post summary

    Fortinet warns that CVE‑2025‑32756, a critical RCE in FortiSandbox, is actively being exploited in the wild; no PoC or patch details are provided.

    0001083
    645 followersView on X
  • Cyber Note 【IT&セキュリティ専門メディア】@CyberNote_media
    PoC

    フォーティネット脆弱性の全容と、今すぐできる対策を詳しく解説 Fortinet製品で確認された脆弱性(CVE-2025-32756)の詳細と対策|PoCも公開済み https://www.cybernote.click/2025/05/27/fortinet%e8%a3%bd%e5%93%81%e3%81%a7%e7%a2%ba%e8%aa%8d%e3%81%95%e3%82%8c%e3%81%9f%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2025-32756%ef%bc%89%e3%81%ae%e8%a9%b3%e7%b4%b0%e3%81%a8%e5%af%be%e7%ad%96poc/?utm_source=rss&utm_medium=rss&utm_campaign=fortinet%25e8%25a3%25bd%25e5%2593%2581%25e3%2581%25a7%25e7%25a2%25ba%25e8%25aa%258d%25e3%2581%2595%25e3%2582%258c%25e3%2581%259f%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25ef%25bc%2588cve-2025-32756%25ef%25bc%2589%25e3%2581%25ae%25e8%25a9%25b3%25e7%25b4%25b0%25e3%2581%25a8%25e5%25af%25be%25e7%25ad%2596poc #ブログ仲間と繋がりたい #Webライター

    Post summary

    The article announces Fortinet CVE-2025-32756, highlights that a PoC has been published, and discusses countermeasures, but offers no technical details, exploit code, or evidence of active exploitation.

    00010291
    32 followersView on X
  • Cyber Note 【IT&セキュリティ専門メディア】@CyberNote_media
    PoC

    【アーカイブ】 Fortinet製品で確認された脆弱性(CVE-2025-32756)の詳細と対策|PoCも公開済み https://www.cybernote.click/2025/05/27/fortinet%e8%a3%bd%e5%93%81%e3%81%a7%e7%a2%ba%e8%aa%8d%e3%81%95%e3%82%8c%e3%81%9f%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2025-32756%ef%bc%89%e3%81%ae%e8%a9%b3%e7%b4%b0%e3%81%a8%e5%af%be%e7%ad%96poc/?utm_source=rss&utm_medium=rss&utm_campaign=fortinet%25e8%25a3%25bd%25e5%2593%2581%25e3%2581%25a7%25e7%25a2%25ba%25e8%25aa%258d%25e3%2581%2595%25e3%2582%258c%25e3%2581%259f%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25ef%25bc%2588cve-2025-32756%25ef%25bc%2589%25e3%2581%25ae%25e8%25a9%25b3%25e7%25b4%25b0%25e3%2581%25a8%25e5%25af%25be%25e7%25ad%2596poc #ブログ仲間と繋がりたい #Webライター

    Post summary

    A proof‑of‑concept for CVE-2025‑32756 on Fortinet products has been published, with accompanying details and countermeasures.

    00010317
    31 followersView on X
  • Cyber Note 【IT&セキュリティ専門メディア】@CyberNote_media
    PoC

    【アーカイブ】 【アーカイブ】 Fortinet製品で確認された脆弱性(CVE-2025-32756)の詳細と対策|PoCも公開済み https://www.cybernote.click/2025/05/27/fortinet%e8%a3%bd%e5%93%81%e3%81%a7%e7%a2%ba%e8%aa%8d%e3%81%95%e3%82%8c%e3%81%9f%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2025-32756%ef%bc%89%e3%81%ae%e8%a9%b3%e7%b4%b0%e3%81%a8%e5%af%be%e7%ad%96poc/?utm_source=rss&utm_medium=rss&utm_campaign=fortinet%25e8%25a3%25bd%25e5%2593%2581%25e3%2581%25a7%25e7%25a2%25ba%25e8%25aa%258d%25e3%2581%2595%25e3%2582%258c%25e3%2581%259f%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25ef%25bc%2588cve-2025-32756%25ef%25bc%2589%25e3%2581%25ae%25e8%25a9%25b3%25e7%25b4%25b0%25e3%2581%25a8%25e5%25af%25be%25e7%25ad%2596poc #ブログ仲間と繋がりたい #Webライター

    Post summary

    The article announces the CVE-2025-32756 vulnerability in Fortinet products, outlines mitigation steps, and confirms a proof‑of‑concept has been published.

    00001157
    31 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-2441 2 - CVE-2026-25253 3 - CVE-2026-1731 4 - CVE-2026-21509 5 - CVE-2025-32756 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists trending CVEs without providing additional details or actionable information.

    00010267
    1.7K followersView on X
  • Cyber Note 【IT&セキュリティ専門メディア】@CyberNote_media
    PoC

    【アーカイブ】 【アーカイブ】 Fortinet製品で確認された脆弱性(CVE-2025-32756)の詳細と対策|PoCも公開済み https://www.cybernote.click/2025/05/27/fortinet%e8%a3%bd%e5%93%81%e3%81%a7%e7%a2%ba%e8%aa%8d%e3%81%95%e3%82%8c%e3%81%9f%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2025-32756%ef%bc%89%e3%81%ae%e8%a9%b3%e7%b4%b0%e3%81%a8%e5%af%be%e7%ad%96poc/?utm_source=rss&utm_medium=rss&utm_campaign=fortinet%25e8%25a3%25bd%25e5%2593%2581%25e3%2581%25a7%25e7%25a2%25ba%25e8%25aa%258d%25e3%2581%2595%25e3%2582%258c%25e3%2581%259f%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25ef%25bc%2588cve-2025-32756%25ef%25bc%2589%25e3%2581%25ae%25e8%25a9%25b3%25e7%25b4%25b0%25e3%2581%25a8%25e5%25af%25be%25e7%25ad%2596poc #ブログ仲間と繋がりたい #Webライター

    Post summary

    The article announces a Fortinet product vulnerability (CVE‑2025‑32756), provides details and a published PoC, but does not mention active exploitation, patches, or false‑positive claims.

    00010286
    30 followersView on X
  • Grok@grok
    Active Exploitation

    **Here's the thorough list of major Fortinet RCE vulns (2021-Apr 2026), focused on critical/unauth ones in perimeter products. EIT = exploited in the wild (CISA KEV + vendor reports).** - **2022**: CVE-2022-42475 (FortiOS SSL VPN RCE, EIT by China actors) - **2023**: CVE-2023-27997 (FortiGate VPN heap overflow RCE, EIT); CVE-2023-33308 (FortiOS/FortiProxy buffer overflow RCE) - **2024**: CVE-2024-21762 (FortiOS SSLVPN RCE, EIT); CVE-2024-23113 (FortiOS/FortiProxy RCE, EIT) - **2025**: CVE-2025-25257 (FortiWeb pre-auth SQLi→RCE, EIT); CVE-2025-32756 (multi-product buffer overflow RCE, EIT); CVE-2025-58034 (FortiWeb cmd injection RCE, EIT) - **2026**: CVE-2026-21643 (FortiClient EMS SQLi RCE, EIT); CVE-2026-35616 (FortiClient EMS unauth RCE, EIT); CVE-2026-39808/39813 (FortiSandbox unauth RCE) Patches released for all; frequency in exposed devices drives the risk.

    Post summary

    The post catalogs a range of Fortinet RCE vulnerabilities, notes their active exploitation in the wild (including CISA KEV mentions), and confirms that patches are available for all listed issues.

    00000152
    8.7M followersView on X
  • ケイ | 副業Webライター🇫🇷⚓⚽@Teeeda_worker
    PoC

    【アーカイブ】 Fortinet製品で確認された脆弱性(CVE-2025-32756)の詳細と対策|PoCも公開済み https://www.cybernote.click/2025/05/27/fortinet%e8%a3%bd%e5%93%81%e3%81%a7%e7%a2%ba%e8%aa%8d%e3%81%95%e3%82%8c%e3%81%9f%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2025-32756%ef%bc%89%e3%81%ae%e8%a9%b3%e7%b4%b0%e3%81%a8%e5%af%be%e7%ad%96poc/?utm_source=rss&utm_medium=rss&utm_campaign=fortinet%25e8%25a3%25bd%25e5%2593%2581%25e3%2581%25a7%25e7%25a2%25ba%25e8%25aa%258d%25e3%2581%2595%25e3%2582%258c%25e3%2581%259f%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25ef%25bc%2588cve-2025-32756%25ef%25bc%2589%25e3%2581%25ae%25e8%25a9%25b3%25e7%25b4%25b0%25e3%2581%25a8%25e5%25af%25be%25e7%25ad%2596poc #ブログ仲間と繋がりたい #Webライター

    Post summary

    The article discloses details and mitigation for Fortinet's CVE-2025-32756, noting that a PoC has already been released.

    00000165
    213 followersView on X
  • ケイ | 副業Webライター🇫🇷⚓⚽@Teeeda_worker
    PoC

    【アーカイブ】 【アーカイブ】 Fortinet製品で確認された脆弱性(CVE-2025-32756)の詳細と対策|PoCも公開済み https://www.cybernote.click/2025/05/27/fortinet%e8%a3%bd%e5%93%81%e3%81%a7%e7%a2%ba%e8%aa%8d%e3%81%95%e3%82%8c%e3%81%9f%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2025-32756%ef%bc%89%e3%81%ae%e8%a9%b3%e7%b4%b0%e3%81%a8%e5%af%be%e7%ad%96poc/?utm_source=rss&utm_medium=rss&utm_campaign=fortinet%25e8%25a3%25bd%25e5%2593%2581%25e3%2581%25a7%25e7%25a2%25ba%25e8%25aa%258d%25e3%2581%2595%25e3%2582%258c%25e3%2581%259f%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25ef%25bc%2588cve-2025-32756%25ef%25bc%2589%25e3%2581%25ae%25e8%25a9%25b3%25e7%25b4%25b0%25e3%2581%25a8%25e5%25af%25be%25e7%25ad%2596poc #ブログ仲間と繋がりたい #Webライター

    Post summary

    The article announces a vulnerability in Fortinet products (CVE‑2025‑32756), confirms a PoC has been released, and notes mitigation measures, but provides no evidence of active exploitation or detailed technical specifications.

    00000281
    213 followersView on X
  • Cyber Note 【IT&セキュリティ専門メディア】@CyberNote_media
    PoC

    【アーカイブ】 【アーカイブ】 Fortinet製品で確認された脆弱性(CVE-2025-32756)の詳細と対策|PoCも公開済み https://www.cybernote.click/2025/05/27/fortinet%e8%a3%bd%e5%93%81%e3%81%a7%e7%a2%ba%e8%aa%8d%e3%81%95%e3%82%8c%e3%81%9f%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2025-32756%ef%bc%89%e3%81%ae%e8%a9%b3%e7%b4%b0%e3%81%a8%e5%af%be%e7%ad%96poc/?utm_source=rss&utm_medium=rss&utm_campaign=fortinet%25e8%25a3%25bd%25e5%2593%2581%25e3%2581%25a7%25e7%25a2%25ba%25e8%25aa%258d%25e3%2581%2595%25e3%2582%258c%25e3%2581%259f%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25ef%25bc%2588cve-2025-32756%25ef%25bc%2589%25e3%2581%25ae%25e8%25a9%25b3%25e7%25b4%25b0%25e3%2581%25a8%25e5%25af%25be%25e7%25ad%2596poc #ブログ仲間と繋がりたい #Webライター

    Post summary

    The article announces a vulnerability (CVE‑2025‑32756) in Fortinet products, publishes a PoC, and discusses general countermeasures.

    00000285
    30 followersView on X
  • ケイ | 副業Webライター🇫🇷⚓⚽@Teeeda_worker
    PoC

    【アーカイブ】 【アーカイブ】 Fortinet製品で確認された脆弱性(CVE-2025-32756)の詳細と対策|PoCも公開済み https://www.cybernote.click/2025/05/27/fortinet%e8%a3%bd%e5%93%81%e3%81%a7%e7%a2%ba%e8%aa%8d%e3%81%95%e3%82%8c%e3%81%9f%e8%84%86%e5%bc%b1%e6%80%a7%ef%bc%88cve-2025-32756%ef%bc%89%e3%81%ae%e8%a9%b3%e7%b4%b0%e3%81%a8%e5%af%be%e7%ad%96poc/?utm_source=rss&utm_medium=rss&utm_campaign=fortinet%25e8%25a3%25bd%25e5%2593%2581%25e3%2581%25a7%25e7%25a2%25ba%25e8%25aa%258d%25e3%2581%2595%25e3%2582%258c%25e3%2581%259f%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25ef%25bc%2588cve-2025-32756%25ef%25bc%2589%25e3%2581%25ae%25e8%25a9%25b3%25e7%25b4%25b0%25e3%2581%25a8%25e5%25af%25be%25e7%25ad%2596poc #ブログ仲間と繋がりたい #Webライター

    Post summary

    The article announces Fortinet vulnerability CVE‑2025‑32756 with disclosed details, mitigation, and a published PoC, but does not provide active exploitation evidence, patches, or technical specifics.

    00000335
    216 followersView on X
CPE platform detail15 entries

15 of 15 entries

PartVendorProductVersionTarget SWTarget HW
HWfortinetforticamera---
OSfortinetforticamera_firmware---
Appfortinetfortimail---
Appfortinetfortindr---
Appfortinetfortindr1.1.0--
Appfortinetfortindr1.2.0--
Appfortinetfortindr1.3.0--
Appfortinetfortindr1.4.0--
Appfortinetfortindr1.5.0--
Appfortinetfortindr7.1.0--
Appfortinetfortindr7.1.1--
Appfortinetfortindr7.6.0--
Appfortinetfortirecorder---
Appfortinetfortivoice---
Appfortinetfortivoice7.2.0--

Explore more