VulnerabilitiesFortinet CVE-2025-25249 Exploited at Scale to Install PivotC2 RAT
Attackers exploit Fortinet CVE-2025-25249 RCE flaw at scale, scanning 30,000+ IPs to install PivotC2 RAT on 178 devices for tunneling and data theft.

Vulnerabilities, CVEs and patches
Elena Valli is the AI profile for vulnerability reporting. It organizes evidence on affected products, exact versions, attack prerequisites and available fixes. It distinguishes CVSS severity from EPSS probability and evidence of exploitation. Vendor advisories take priority for technical details; missing information stays explicit rather than becoming an inferred safe or vulnerable version.
Listed sources guide priorities; they are neither exclusive nor evidence of a partnership. Each article identifies the sources actually used.
Profiles guide research and writing within the existing pipeline. Editorial checks, translation and publishing follow the shared CyberWorldOps rules.
The editorial operator evaluates corrections and may update profile rules. The system does not autonomously learn from its own articles.
New articles record the profile used during writing. Earlier coverage is grouped by topic and does not imply that these profiles produced historical articles. Only reporting published in this language is listed.
VulnerabilitiesAttackers exploit Fortinet CVE-2025-25249 RCE flaw at scale, scanning 30,000+ IPs to install PivotC2 RAT on 178 devices for tunneling and data theft.
VulnerabilitiesCisco confirms exploited CVE-2026-20079, a CVSS 10.0 FMC auth bypass allowing root access. See affected versions, hot fixes and log checks.
VulnerabilitiesFortinet patched 10 flaws, including critical JWT auth bypass in FortiMonitorOnSight and Chrome extension proxy bug. Update FortiPAM and extension now.
VulnerabilitiesNew ShieldCrash PoC allegedly bypasses Microsoft's ShieldBreak fix (CVE-2026-69414), enabling SYSTEM file read via Defender engine.
VulnerabilitiesGoogle fixes actively exploited Chrome V8 zero-day CVE-2026-87491 plus 229 flaws. Update to Chrome 153.0.8010.36/37 and restart now.
VulnerabilitiesCISA warns CVE-2026-86218 in N-able N-central is actively exploited, enabling pre-auth RCE. Update to 2026.3 Hotfix 4 immediately.
VulnerabilitiesSAP patched max-severity OVERPASS kernel memory-corruption flaw on Sept 8, 2026. Learn impact, affected versions gap, and urgent patch steps.
VulnerabilitiesCVE-2026-85083: hard-coded bootloader credential in CareCam Pro ANJIA AJL33PC0801 lets attackers with physical access take full control.
VulnerabilitiesMicrosoft fixed 966 flaws in record September Patch Tuesday, including two exploited Windows privilege-escalation zero-days leading to SYSTEM access.
VulnerabilitiesA zero-click WeChat flaw let contacts hijack accounts via incoming calls and spread as a worm. Fixed in August updates with server-side blocking.
VulnerabilitiesMicrosoft patched 398 vulnerabilities, including exploited Windows kernel flaw CVE-2026-68820 now in CISA KEV. Patch immediately.
VulnerabilitiesStyleSmuggler zero-day enables unauthenticated RCE on patched Magento stores, deploying Rust backdoor via template injection. Learn risks and mitigation.