Thursday, September 10, 2026

CISA Adds FortiGuard Vulnerability to KEV Catalog – 9-9-26

Yesterday, CISA announced that it had added a heap-based buffer overflow vulnerability in the FortiGuard FortiOS and FortiSwitchManager products to their Known Exploited Vulnerabilities (KEV) catalog. FortiGuard published their advisory on the vulnerability in January 2026, and most recently updated it in February. Fixed versions are available. 

On Tuesday, SOCRadar published an article detailing their discovery of the “PivotC2, a Node.js Remote Access Trojan (RAT) designed specifically as a FortiGate post-exploitation tool.” They report seeing evidence of exploits in the wild as far back as July of this year. The article provides a detailed technical analysis of the fortirun.bin component of PivotC2 as well as indicators of compromise. 

CISA has directed federal agencies using the affected FortiGuard products to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” 

A compliance deadline of September 12th, 2026 has been established. 

No comments:

 
/* Use this with templates/template-twocol.html */