Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SOCRadar says it assessed 178 FortiGate devices as infected with PivotC2 in files recovered during its investigation—not in a global census or an independently confirmed count. Its September 8, 2026 report describes exploitation of CVE-2025-25249, a vulnerability in FortiOS and FortiSwitchManager, followed by malware that could turn a perimeter appliance into a foothold for remote access, network discovery and credential theft.

What is PivotC2?

SOCRadar describes PivotC2 as a Node.js post-exploitation remote-access tool (RAT) built for FortiGate appliances. In this context, “post-exploitation” means the malware is used after an attacker has gained code execution; it is not the vulnerability or the initial exploit itself.

Based on its analysis of recovered files, SOCRadar says PivotC2 could provide an interactive shell, transfer files, proxy traffic through SOCKS5 or HTTP, set up port forwarding, scan networks, and collect FortiGate configuration data. The report also describes functionality for decrypting credentials stored in appliance configuration. These are capabilities attributed to the recovered tooling; they do not establish that every capability was used on every infected device.

Is CVE-2025-25249 being exploited in the wild?

SOCRadar reported on September 8, 2026, that it had identified exploitation in the wild since at least July 2026 and that activity was ongoing at the time of publication. Its report calls CVE-2025-25249 a heap-based buffer overflow in the cw_acd daemon in FortiOS and FortiSwitchManager. SOCRadar says specially crafted requests could enable remote, unauthenticated code or command execution.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

That is the status reported by SOCRadar on that date, not a live confirmation of activity today. The campaign-specific findings in ThaiCERT’s September 11 summary and SecurityWeek’s September 2026 coverage are secondary accounts of SOCRadar’s work, not independent validation of its infection tally or technical findings.

What does the 178-device figure mean?

In files recovered during its investigation, SOCRadar says it found a list of more than 30,000 targeted FortiGate IP addresses and 178 devices it assessed as exploited and infected with PivotC2. Those figures describe SOCRadar’s recovered campaign dataset. They are not a count of all exposed or compromised FortiGate devices worldwide, and the assessment does not establish the likelihood that any particular organization was compromised.

Rank #2
Sale
FortiGate-60F Firewall Appliance - 10 Gigabit Ethernet RJ45 Ports, Includes DMZ, WAN & Internal Ports (Appliance Only, No Subscription) (FG-60F)
  • Extensive Connectivity Options: The FortiGate 60F is designed with 10 GE RJ45 ports, including 2 WAN ports, 1 DMZ port, and 7 internal ports, offering broad flexibility and high-density connections for diverse enterprise networking needs.
  • Superior Performance for Secure Networks: Features powerful system-on-a-chip acceleration to deliver top-tier security with 1.4 Gbps IPS throughput and 700 Mbps threat protection throughput, ensuring effective defense against advanced threats.
  • Enhanced SSL Inspection and SD-WAN Capabilities: Utilizes purpose-built security processor technology to provide the industry's highest SSL inspection performance and robust SD-WAN functionality for secure, high-speed network operations.
  • Simple and Effective Management: Comes equipped with a user-friendly management console that supports comprehensive network automation and visibility, alongside Zero Touch Integration with Fortinet's Security Fabric for streamlined deployment.
  • Advanced Security Features: Leverages continuous threat intelligence from AI-powered FortiGuard Labs, identifying and mitigating both known and unknown threats, enhancing security across all network traffic, whether encrypted or not.

SOCRadar also reports two full intrusions against U.S.-based organizations with confirmed data exfiltration. That finding concerns those two investigated intrusions; it does not show that data was taken from every device in the 178-device set.

Why can a compromised edge appliance be a useful place to hide?

A FortiGate sits at a network boundary and may handle traffic between the internet and internal systems, as well as VPN or other organizational connectivity. If an attacker gains control of the appliance, its position can provide a useful vantage point for reaching or surveying systems behind that boundary. A device that administrators expect to run network services can also make malicious activity harder to distinguish from routine appliance operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
FortiGate-40F Firewall Appliance plus 1 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) (FG-40F-BDL-950-12)
  • INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 1 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.

SOCRadar’s technical account illustrates the risk without proving that every infected device was used in the same way: the reported PivotC2 capabilities include interactive access, traffic forwarding, scanning and harvesting configuration data. The report also describes functions to decrypt credentials found in that configuration. Those capabilities can support further access, but the campaign report does not establish a specific downstream outcome for every assessed device.

How did SOCRadar describe the infection chain?

SOCRadar says the recovered exploit flow used a binary to target the vulnerable daemon, established a reverse shell through Node.js, and then ran a JavaScript stager. That stager retrieved a second-stage payload and saved it as /tmp/.i.js. The report says PivotC2 then maintained outbound TLS command-and-control communications.

Rank #4
Fortinet FortiGate-30G Firewall for Small Offices with 4 Gigabit Ethernet RJ45 Ports (FG-30G)
  • Single appliance with integrated firewalling, SD-WAN and Wi-Fi controller reduces complexity of WLAN management. Its zero-touch deployment helps optimize your onboarding experience.
  • Built on a patented secure processor, this compact network firewall delivers the highest level of security and performance in its class – 800 Mbps IPS | 500 Mbps threat protection.
  • User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
  • Compact and fanless design equipped with 4 GE RJ45 ports (1 WAN port and 3 internal ports) provide essential connectivity and flexibility for various network configurations in a small-scale environment.
  • Fortinet is the most deployed and trusted firewall from businesses worldwide with 99.98% security effectiveness, surpassing competition. Fortinet is the only vendor recognized as a firewall leader 13 consecutive years by Gartner.

These details come from SOCRadar’s recovered files and reverse engineering. The report assesses the campaign as Russian-speaking and financially motivated with high confidence; this is the research team’s attribution assessment, not an established identification of the operators. Its suggestion that AI may have assisted malware development is likewise an assessment based on inline comments and usage guidance, not confirmation of how the tool was authored.

Which versions does SOCRadar list as fixed?

The following are the fixed releases listed in SOCRadar’s report. Confirm the applicable upgrade path and supported target release in Fortinet’s current advisory and product documentation before making a change; the report’s version mapping is not a substitute for checking your product’s supported upgrade sequence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Product branch Fixed release listed by SOCRadar
FortiOS 7.6 7.6.4 or later
FortiOS 7.4 7.4.9 or later
FortiOS 7.2 7.2.12 or later
FortiOS 7.0 7.0.18 or later
FortiSwitchManager 7.2 7.2.7 or later
FortiSwitchManager 7.0 7.0.6 or later
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should FortiGate and FortiSwitchManager administrators do?

  1. Identify affected exposure. Inventory FortiOS and FortiSwitchManager versions, determine which software branches are deployed, and check whether relevant control traffic is reachable from the internet.
  2. Upgrade along a supported path. Apply the appropriate fixed release or a later supported release for the installed branch. Verify the target and upgrade sequence against Fortinet’s current guidance before proceeding.
  3. Limit exposed CAPWAP control traffic. Where appropriate for the deployment, restrict external CAPWAP control access. SOCRadar specifically recommends disabling fabric service on external interfaces or using a local-in policy to drop UDP ports 5246–5249. Confirm the effect on required services before changing production firewall policy.
  4. Hunt for signs of execution or command-and-control. Review appliance sessions, files, processes and activity for suspicious behavior. SOCRadar names /tmp/.i.js, unauthorized Node.js execution and connections matching its reported indicators as investigation leads. Treat those indicators as specific to its report and verify them against current threat intelligence before using them for blocking or detection.
  5. Respond to evidence of compromise. Follow your incident-response procedures and relevant vendor guidance. Assume secrets stored in the appliance configuration may have been exposed; assess and rotate applicable administrative, VPN, LDAP, wireless and IPsec credentials. Also investigate possible lateral access and evaluate incident-reporting obligations.

SOCRadar’s report is the primary public technical account identified for the campaign-specific malware analysis and figures. ThaiCERT’s September 11, 2026 summary and SecurityWeek’s September 2026 article provide secondary coverage. Because those summaries repeat SOCRadar’s findings, they do not make the campaign totals independently confirmed. The material available here does not establish specific Fortinet advisory wording or a CISA KEV listing date, so administrators should check current official records for those details.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.