Skip to content
COOEY

EXPOSURES › CVE-2025-32756

CVE-2025-32756

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-05-14 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-32756 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Fortinet products have a stack-based buffer overflow allowing remote code execution without authentication, and are currently being exploited in the wild.

Multiple Fortinet products (FortiFone, FortiVoice, FortiNDR, FortiMail) contain a remotely exploitable buffer overflow, enabling arbitrary code execution. DIB organizations using these products face immediate risk of compromise and potential CMMC compliance failures if not promptly patched. Immediate patching and vulnerability scanning are required.

Shame score — The vulnerability's exploitation in the wild and lack of authentication requirements demonstrate a significant security oversight by Fortinet.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.