{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fortimail--7.0.9-7.2.8-7.4.5-7.6.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortindr:*:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortindr:1.1.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortindr:1.2.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortindr:1.3.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortindr:1.4.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortindr:1.5.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortindr:7.1.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortindr:7.1.1:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortindr:7.6.0:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortirecorder:*:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortivoice:*:*:*:*:*:*:*:*","cpe:2.3:a:fortinet:fortivoice:7.2.0:*:*:*:*:*:*:*","cpe:2.3:o:fortinet:forticamera_firmware:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2025-32756"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FortiMail (\u003c 7.0.9, 7.2.8, 7.4.5, 7.6.3)","FortiNDR (\u003c 7.0.7, 7.2.5, 7.4.8, 7.6.1)","FortiRecorder (\u003c 6.4.6, 7.0.6, 7.2.4)","FortiVoice (\u003c 6.4.11, 7.0.7, 7.2.1)","FortiCamera (\u003c 2.1.4)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","buffer-overflow","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Fortinet"],"content_html":"\u003cp\u003eCVE-2025-32756 is a critical stack-based buffer overflow vulnerability affecting a wide range of Fortinet products, including FortiMail, FortiNDR, FortiRecorder, FortiVoice, and FortiCamera. The flaw exists in the handling of the 'enc' parameter within the 'AuthHash' cookie when processed by the '/remote/hostcheck_validate' endpoint. Because this endpoint is reachable without authentication, remote attackers can trigger the buffer overflow by sending specifically crafted HTTP requests. Public proof-of-concept exploit code has been released, allowing for the discovery and exploitation of vulnerable systems. Defenders should prioritize patching or restricting access to the vulnerable endpoint immediately, as this vulnerability carries a CVSS score of 9.8.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance or network scanning to identify reachable Fortinet devices.\u003c/li\u003e\n\u003cli\u003eAttacker targets the '/remote/hostcheck_validate' URI on the discovered Fortinet appliance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request containing a specially formed 'AuthHash' cookie.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a payload into the 'enc' parameter within the cookie, designed to exceed the allocated stack buffer.\u003c/li\u003e\n\u003cli\u003eThe target Fortinet appliance processes the cookie, triggering the buffer overflow condition during memory handling.\u003c/li\u003e\n\u003cli\u003eAttacker potentially gains control of the instruction pointer to achieve arbitrary code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2025-32756 results in unauthenticated remote code execution, granting attackers the ability to compromise the confidentiality, integrity, and availability of the affected Fortinet appliances. These devices are often positioned at the network perimeter, and their compromise could facilitate deeper network penetration or interception of organizational traffic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade FortiMail to 7.0.9, 7.2.8, 7.4.5, 7.6.3 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade FortiNDR to 7.0.7, 7.2.5, 7.4.8, 7.6.1 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade FortiRecorder to 6.4.6, 7.0.6, 7.2.4 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade FortiVoice to 6.4.11, 7.0.7, 7.2.1 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade FortiCamera to 2.1.4 or later.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST or GET requests targeting the '/remote/hostcheck_validate' path, specifically looking for unusually long or malformed 'AuthHash' cookie strings.\u003c/li\u003e\n\u003cli\u003eImplement access controls to restrict exposure of administrative or authentication-related endpoints to untrusted networks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T02:08:58Z","date_published":"2026-09-10T02:08:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-32756-fortinet-rce/","summary":"A critical unauthenticated stack-based buffer overflow vulnerability, tracked as CVE-2025-32756, affects multiple Fortinet products and can be triggered via a crafted 'enc' parameter in the 'AuthHash' cookie.","title":"Critical RCE Vulnerability in Fortinet Products via AuthHash Cookie (CVE-2025-32756)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-32756-fortinet-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - FortiMail (\u003c 7.0.9, 7.2.8, 7.4.5, 7.6.3)","version":"https://jsonfeed.org/version/1.1"}