Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Fortinet RCE flaw exploited to deploy PivotC2 backdoor.

Attackers are abusing a heap‑based buffer overflow in FortiOS and FortiSwitchManager to install the PivotC2 Node.js RAT, a post‑exploitation tool that provides shell access, tunneling, scanning and configuration harvesting. SOCRadar says more than 30,000 IPs were targeted and 178 devices infected, with intrusions concentrated in the U.S. and attributed to a Russian‑speaking actor. CISA has added the vulnerability to its KEV catalog and ordered rapid patching, as exploitation has been ongoing since mid‑2026. Fixes are available in recent FortiOS and FortiSwitchManager versions, and organizations are urged to update immediately.

Read more:

https://www.securityweek.com/fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks/