An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access trojan (RAT). This makes the affected devices key points for spying and stealing information.
The SOCRadar Threat Research Unit has found that attackers are using CVE-2025-25249. This is a serious flaw in the cw_acd daemon in FortiOS and FortiSwitchManager.
Rated 9.8 on the CVSSv3 scale, this weakness lets attackers from afar run any code they want by sending special requests to the CAPWAP Control service, which is found on UDP port 5246.
Fortinet uses CAPWAP to control wireless access points from one place. This makes the system available on many FortiGate devices that connect to the internet. The affected versions include FortiOS 6.4 to 7.6.3 and FortiSwitchManager 7.0.x and 7.2.x, but Fortinet released fixes after the news was shared on January 13, 2026.
Administrators should limit outside access to CAPWAP Control ports, look for strange Node.js processes and files like /tmp/.i.js on open devices, and review active sessions for links to known bad IP addresses.
Because PivotC2 collects device settings in bulk, any group that sees hints of a breach should consider all saved passwords, like SSL-VPN, LDAP, and IPSec keys, to be unsafe and change them right away.
FortiSandbox Vulnerability
Fortinet has revealed a serious vulnerability in its FortiSandbox platform. It warn that attackers without permission could take advantage of issues in the web interface to steal sensitive information without needing valid logins.
The flaw, tracked as CVE-2026-26084, stems from improper access control in the graphical user interface component that FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS all share, and it has been assigned a CVSS v3.1 score of 8.9, placing it firmly in the high-severity category.
FortiOS and FortiProxy ZTNA Validation Vulnerabilit:
Fortinet has revealed a serious flaw with certificate validation in the Agentless ZTNA portal of FortiOS and FortiProxy. This issue could allow an unauthorized remote attacker to intercept traffic between the ZTNA portal and the website it connects to.
Tracked as CVE-2026-84393 and noted in advisory FG-IR-26-174, the flaw was released on September 8, 2026, and has a CVSSv3 score of 7.3. The weakness comes from a flawed certificate check, classified as CWE-295, in the Agentless ZTNA portal part. Zero Trust Network Access portals aim to create safe connections with identity checks between users and internal apps without needing a complete VPN client.
InfoSecBulletin Cybersecurity for mankind
