Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM APE1808 Devices (SSA-864900) — Including Actively Exploited FortiCloud SSO Bypass (CVE-2025-59718/-59719) and FortiOS Heap Overflow (CVE-2025-25249)

Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM (TL-2026-2486), also tracked as SSA-864900, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-13. It has no confirmed attribution, affects Siemens RUGGEDCOM APE1808 (running Fortigate NGFW), references 28 CVEs (CVE-2024-32122, CVE-2024-50562, CVE-2024-52963), maps to 9 MITRE ATT&CK techniques (T1059.007, T1059.008, T1190), and is covered by 9 detection rules and 10 indicators of compromise.

Key facts for TL-2026-2486

Threat ID
TL-2026-2486
Also known as
SSA-864900
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-13
Last reviewed
2026-09-13
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
critical manufacturing, energy, transportation systems
Target regions
Global
Detection rules
9
Indicators of compromise
10

Malware and tooling in Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM

Malware and tooling: PivotC2

Siemens SSA-864900 (v2.0, 2026-08-11) lists 28 CVEs affecting RUGGEDCOM APE1808 industrial edge appliances running Fortigate NGFW below V7.4.9 or V7.6.6. Two of the CVEs — CVE-2025-59718 and CVE-2025-59719, both CVSS 9.8 FortiCloud SSO signature-verification bypasses — are confirmed under active exploitation and listed in CISA's KEV catalog; CVE-2025-25249, a critical unauthenticated FortiOS heap overflow, has also been observed exploited to deploy a post-exploitation RAT.

How Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM works

Siemens Security Advisory SSA-864900, first published 2025-05-13 and updated to v2.0 on 2026-08-11, documents 28 Fortinet CVEs that carry over to RUGGEDCOM APE1808 — a hardened industrial edge-computing platform deployed at the OT/IT boundary in energy, transportation, and critical-manufacturing networks — because the device runs Fortigate NGFW as its hosted firewall/security application. Devices running Fortinet NGFW below V7.4.9 are affected by 19 of the CVEs; devices below V7.6.6 are affected by 9 of the CVEs. Siemens' remediation is unchanged from typical ICS advisories: apply the vendor firmware update, since Siemens does not independently patch the Fortinet component.

The most severe items in the set are CVE-2025-59718 and CVE-2025-59719 (CVSS 3.1 9.8, CWE-347 Improper Verification of Cryptographic Signature), disclosed by Fortinet on 2025-12-09 under PSIRT advisory FG-IR-25-647. Both allow an unauthenticated attacker to submit a crafted SAML response message that the device's FortiCloud SSO login flow fails to properly validate, granting administrative access without credentials. CVE-2025-59718 affects FortiOS, FortiProxy, and FortiSwitchManager; CVE-2025-59719 affects FortiWeb. Although FortiCloud SSO is disabled in factory defaults, Arctic Wolf and Rapid7 note it is silently re-enabled when a device is registered to FortiCare via the GUI unless an administrator explicitly opts out — a significant real-world exposure driver. Arctic Wolf observed malicious SSO logins beginning 2025-12-12, CISA added CVE-2025-59718 to its KEV catalog on 2025-12-16, and Rapid7 confirmed broad in-the-wild exploitation against internet-exposed FortiGate devices by 2026-01-16. Post-compromise, attackers consistently authenticate as admin and immediately download the device's system configuration file, which contains hashed local credentials for further lateral movement or offline cracking.

CVE-2025-25249 (Siemens-listed CVSS 3.1 8.1; independently tracked by NVD/CISA partners at up to 9.8, CWE-122 Heap-Based Buffer Overflow, Fortinet PSIRT FG-IR-25-084) is a remotely triggerable, unauthenticated heap overflow in the FortiOS/FortiSwitchManager cw_acd daemon reachable via crafted packets, and is also listed in CISA's KEV catalog as actively exploited. SOCRadar reports exploitation of this flaw has been used to deploy "PivotC2," a FortiGate-targeting post-exploitation RAT.

A cluster of memory-corruption CVEs (CVE-2025-53843 stack overflow in the capwap daemon, FG-IR-25-358, CVSS 7.5; CVE-2025-53844 out-of-bounds write in capwap, FG-IR-26-123, CVSS 8.8; CVE-2025-58413 unauthenticated stack overflow in wireless-controller packet processing, CVSS 7.5; CVE-2026-59837 privileged stack overflow, CVSS 6.6) let an attacker controlling — or spoofing — a Security-Fabric-connected FortiAP, FortiSwitch, or FortiExtender execute code on the parent FortiGate, which is directly relevant to RUGGEDCOM APE1808 deployments that federate multiple fabric-connected devices at OT network edges. Separately, CVE-2025-53744 (FG-IR-25-173, CWE-266, CVSS 7.2) lets an authenticated high-privilege admin escalate to super-admin by registering the FortiGate to a malicious FortiManager instance, abusing the implicit trust relationship in Security Fabric registration.

The remaining 21 CVEs are lower-severity issues spanning certificate-validation weaknesses (CVE-2025-24471 accepts revoked certificates; CVE-2025-25253 certificate host mismatch in the ZTNA proxy — both enabling adversary-in-the-middle positioning), information disclosure (CVE-2025-25250 SSL-VPN settings exposure via crafted URL; CVE-2025-43892 and CVE-2026-59840 buffer over-reads; CVE-2025-31514 2FA data in logs), input-validation bugs (CVE-2025-31366 reflected XSS; CVE-2025-62675/CVE-2025-62826 HTTP response splitting; CVE-2025-47890 open redirect; CVE-2025-25248 integer overflow in SSL-VPN bookmarks), a CLI scripting-engine issue (CVE-2025-67862, CWE-1244, Lua script execution via CLI), a DNS-filter bypass (CVE-2024-55599), a session-management flaw (CVE-2024-50562), a trusted-host-policy bypass (CVE-2025-54821), a null-pointer DoS (CVE-2025-58903), and an IPsec out-of-bounds write DoS (CVE-2024-52963).

No public exploitation or PoC is stated for the RUGGEDCOM-specific advisory itself, but several of the underlying Fortinet CVEs (CVE-2025-59718, CVE-2025-59719, CVE-2025-25249) are independently confirmed as actively exploited in the wild against FortiGate deployments generally, which raises material risk for any RUGGEDCOM APE1808 unit left on an unpatched Fortigate NGFW branch.

MITRE ATT&CK techniques used in TL-2026-2486

Execution

T1059.007 JavaScript; T1059.008 Network Device CLI

Initial Access

T1190 Exploit Public-Facing Application; T1199 Trusted Relationship

Impact

T1499.004 Application or System Exploitation

Credential Access

T1552 Unsecured Credentials; T1552.001 Credentials In Files; T1557 Adversary-in-the-Middle

defense-impairment

T1556 Modify Authentication Process

Affected products and versions in Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM

  • Siemens — RUGGEDCOM APE1808 (running Fortigate NGFW)
    Vulnerable versions: all versions with Fortinet NGFW < V7.4.9; all versions with Fortinet NGFW < V7.6.6
    Fixed in: Fortinet NGFW V7.4.9 or later (V7.4.10+ recommended); Fortinet NGFW V7.6.6 or later
  • Fortinet — FortiOS
    Vulnerable versions: 6.0; 6.2; 6.4; 7.0.0-7.0.17; 7.2.0-7.2.11; 7.4.0-7.4.9; 7.6.0-7.6.4
    Fixed in: 7.4.9+ / 7.4.10+; 7.6.6+
  • Fortinet — FortiProxy
    Vulnerable versions: versions predating FG-IR-25-647 fixed builds
    Fixed in: per FG-IR-25-647
  • Fortinet — FortiSwitchManager
    Vulnerable versions: 7.0.0-7.0.5; 7.2.0-7.2.6
    Fixed in: per FG-IR-25-647 / FG-IR-25-084
  • Fortinet — FortiWeb
    Vulnerable versions: 7.4.0-7.4.9; 7.6.0-7.6.4; 8.0.0
    Fixed in: per FG-IR-25-647
  • Fortinet — FortiSASE
    Vulnerable versions: 25.3.b
    Fixed in: per FG-IR-25-... CVE-2025-58413 remediation

Remediation for Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM

Patches

  • Fortinet PSIRT FG-IR-25-647 — CVE-2025-59718, CVE-2025-59719
  • Fortinet PSIRT FG-IR-25-084 — CVE-2025-25249
  • Fortinet PSIRT FG-IR-25-173 — CVE-2025-53744
  • Fortinet PSIRT FG-IR-25-358 — CVE-2025-53843
  • Fortinet PSIRT FG-IR-26-123 — CVE-2025-53844
  • Siemens SSA-864900 v2.0 — update Fortigate NGFW to V7.4.9+ or V7.6.6+

Immediate actions

  • Update Fortigate NGFW on RUGGEDCOM APE1808 to V7.4.9+ (V7.4.10+ per the follow-on ICSA-26-071-02 guidance) or V7.6.6+ depending on the affected range
  • Disable the FortiCloud SSO login feature until patched, and explicitly opt out of its auto-enable during FortiCare device registration (CVE-2025-59718, CVE-2025-59719)
  • Restrict Security Fabric registration to trusted, pinned FortiManager instances only and audit recent fabric registration events (CVE-2025-53744)
  • Treat any device that logged an unexpected FortiCloud SSO admin session as compromised: rotate all local credentials and re-issue certificates, since attackers download and can crack the hashed credentials in the exported configuration

Workarounds

  • Disable the wireless-controller/capwap daemon if FortiAP/FortiSwitch management is not required (CVE-2025-53844, CVE-2025-58413)
  • Configure IPsec phase1-interface with psk authentication or disable digital-signature-auth (CVE-2024-52963)
  • Remove Security Fabric access from untrusted interfaces (CVE-2025-25249 mitigation per Fortinet PSIRT)

Longer-term hardening

  • Adopt Siemens' Operational Guidelines for Industrial Security for all RUGGEDCOM APE1808 deployments
  • Segment the OT/IT boundary so FortiGate management interfaces on RUGGEDCOM APE1808 are never internet-exposed
  • Continuously monitor CISA's KEV catalog and Fortinet PSIRT advisories (FG-IR-25-647, FG-IR-25-084, FG-IR-25-173, FG-IR-25-358, FG-IR-26-123) for this platform
  • Require mutual authentication / certificate pinning between Security-Fabric-connected FortiAP, FortiSwitch, FortiExtender, and FortiManager devices to reduce the capwap/fabric-trust attack surface

CVEs associated with Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM

  • CVE-2024-32122
  • CVE-2024-50562
  • CVE-2024-52963
  • CVE-2024-55599
  • CVE-2025-22862
  • CVE-2025-24471
  • CVE-2025-25248
  • CVE-2025-25249
  • CVE-2025-25250
  • CVE-2025-25253
  • CVE-2025-31366
  • CVE-2025-31514
  • CVE-2025-43892
  • CVE-2025-47890
  • CVE-2025-53744
  • CVE-2025-53843
  • CVE-2025-53844
  • CVE-2025-54821
  • CVE-2025-57740
  • CVE-2025-58413
  • CVE-2025-58903
  • CVE-2025-59718
  • CVE-2025-59719
  • CVE-2025-62675
  • CVE-2025-62826
  • CVE-2025-67862
  • CVE-2026-59837
  • CVE-2026-59840

Weaknesses (CWE) in Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM

CWE-522, CWE-613, CWE-787, CWE-358, CWE-288, CWE-295, CWE-190, CWE-122, CWE-200, CWE-297

Timeline of Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM

  • Siemens ProductCERT first publishes SSA-864900 covering Fortinet CVEs affecting RUGGEDCOM APE1808 devices running Fortigate NGFW.
  • Fortinet discloses CVE-2025-59718 and CVE-2025-59719 (FortiCloud SSO signature-verification bypass) under PSIRT advisory FG-IR-25-647, alongside CVE-2025-25249 (FG-IR-25-084) and CVE-2025-53744 (FG-IR-25-173).
  • Arctic Wolf observes malicious FortiCloud SSO admin logins on internet-facing FortiGate appliances, days after CVE-2025-59718/-59719 disclosure.
  • CISA adds CVE-2025-59718 to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation.
  • Rapid7 observes exploitation attempts against honeypots; non-functional public PoC exploit code for CVE-2025-59718 begins circulating on GitHub.
  • VulnCheck analysis finds the two public CVE-2025-59718 PoCs circulating at the time are fake or non-functional.
  • Rapid7 confirms broad active exploitation of CVE-2025-59718/-59719 against internet-exposed FortiGate devices.
  • Siemens updates SSA-864900 to v2.0, expanding the enumerated CVE set to 28 entries affecting RUGGEDCOM APE1808 devices running Fortigate NGFW below V7.4.9 or V7.6.6.

Sources cited for Multiple Vulnerabilities in Fortigate NGFW on RUGGEDCOM

More in vulnerability

Detection coverage for TL-2026-2486

As of 2026-09-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2486 across Splunk SPL, Microsoft KQL and Sigma, covering 10 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats