{"total":3,"items":[{"id":581,"title":"Kwetsbaarheid verholpen in Fortinet FortiMail","original_title":"Kwetsbaarheid verholpen in Fortinet FortiMail","source_rating":null,"summary":"Fortinet heeft een kwetsbaarheid verholpen in FortiMail. FortiMail bevat een kritieke kwetsbaarheid (CVE-2026-104286) in de verwerking van bestandspaden, veroorzaakt door een combinatie van Path Traversal (CWE-22) en onvoldoende neutralisatie van NULL-bytes (CWE-158). Een niet-geauthenticeerde aanvaller kan via speciaa","ai":false,"actions":[],"url":"https://advisories.ncsc.nl/advisory?id=NCSC-2026-0398","type":"advisory","language":"nl","published_at":"2026-10-02T07:21:47+00:00","severity":"kritiek","priority":70,"vendors":["Fortinet"],"cves":[{"id":"CVE-2026-104286","cvss":9.8,"epss":null,"epss_percentile":null,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.8,"epss_max":null,"source_count":2,"ncsc":{"kans":"M","schade":"H"},"source":{"slug":"ncsc-nl-advisories","name":"NCSC-NL Security Advisories","category":"overheid","country":"NL","license":"CC0 (Rijksoverheid)","reuse":"open"},"bundle":null},{"id":580,"title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","original_title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","source_rating":null,"summary":"Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.\n\nVereiste actie: Apply mitigations in accordance with vendor instructi","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104286","type":"kev","language":"en","published_at":"2026-10-01T00:00:00+00:00","severity":"hoog","priority":55,"vendors":["Fortinet"],"cves":[{"id":"CVE-2026-104286","cvss":9.8,"epss":null,"epss_percentile":null,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.8,"epss_max":null,"source_count":2,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null},{"id":162,"title":"CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability","original_title":"CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability","source_rating":null,"summary":"Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.\n\nVereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prio","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-25249","type":"kev","language":"en","published_at":"2026-09-09T00:00:00+00:00","severity":"hoog","priority":55,"vendors":["Fortinet"],"cves":[{"id":"CVE-2025-25249","cvss":9.8,"epss":0.03859,"epss_percentile":0.89847,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.8,"epss_max":0.03859,"source_count":1,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null}]}