{"total":3,"items":[{"id":582,"title":"[NIEUW] [kritiek] Fortinet FortiMail: Kwetsbaarheid maakt manipulatie van bestanden mogelijk","original_title":"[NEU] [kritisch] Fortinet FortiMail: Schwachstelle ermöglicht Manipulation von Dateien","source_rating":"kritiek","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3701","type":"advisory","language":"de","published_at":"2026-10-02T09:11:29+00:00","severity":"hoog","priority":45,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":581,"title":"Kwetsbaarheid verholpen in Fortinet FortiMail","original_title":"Kwetsbaarheid verholpen in Fortinet FortiMail","source_rating":null,"summary":"Fortinet heeft een kwetsbaarheid verholpen in FortiMail. FortiMail bevat een kritieke kwetsbaarheid (CVE-2026-104286) in de verwerking van bestandspaden, veroorzaakt door een combinatie van Path Traversal (CWE-22) en onvoldoende neutralisatie van NULL-bytes (CWE-158). Een niet-geauthenticeerde aanvaller kan via speciaa","ai":false,"actions":[],"url":"https://advisories.ncsc.nl/advisory?id=NCSC-2026-0398","type":"advisory","language":"nl","published_at":"2026-10-02T07:21:47+00:00","severity":"kritiek","priority":70,"vendors":["Fortinet"],"cves":[{"id":"CVE-2026-104286","cvss":9.8,"epss":0.02201,"epss_percentile":0.81912,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.8,"epss_max":0.02201,"source_count":2,"ncsc":{"kans":"M","schade":"H"},"source":{"slug":"ncsc-nl-advisories","name":"NCSC-NL Security Advisories","category":"overheid","country":"NL","license":"CC0 (Rijksoverheid)","reuse":"open"},"bundle":null},{"id":580,"title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","original_title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","source_rating":null,"summary":"Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.\n\nVereiste actie: Apply mitigations in accordance with vendor instructi","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104286","type":"kev","language":"en","published_at":"2026-10-01T00:00:00+00:00","severity":"hoog","priority":55,"vendors":["Fortinet"],"cves":[{"id":"CVE-2026-104286","cvss":9.8,"epss":0.02201,"epss_percentile":0.81912,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.8,"epss_max":0.02201,"source_count":2,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null}]}