EXPOSURES › CVE-2025-32756
CVE-2025-32756
HIGH ⌖ ON CISA KEV · EXPLOITEDFortinet products have a stack-based buffer overflow allowing remote code execution without authentication, and are currently being exploited in the wild.
Multiple Fortinet products (FortiFone, FortiVoice, FortiNDR, FortiMail) contain a remotely exploitable buffer overflow, enabling arbitrary code execution. DIB organizations using these products face immediate risk of compromise and potential CMMC compliance failures if not promptly patched. Immediate patching and vulnerability scanning are required.
Shame score — The vulnerability's exploitation in the wild and lack of authentication requirements demonstrate a significant security oversight by Fortinet.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.