{"total":29,"items":[{"id":582,"title":"[NIEUW] [kritiek] Fortinet FortiMail: Kwetsbaarheid maakt manipulatie van bestanden mogelijk","original_title":"[NEU] [kritisch] Fortinet FortiMail: Schwachstelle ermöglicht Manipulation von Dateien","source_rating":"kritiek","summary":"","ai":false,"actions":[],"url":"https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3701","type":"advisory","language":"de","published_at":"2026-10-02T09:11:29+00:00","severity":"hoog","priority":45,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"bsi-wid","name":"BSI CERT-Bund WID","category":"overheid","country":"DE","license":"© BSI","reuse":"excerpt"},"bundle":null},{"id":581,"title":"Kwetsbaarheid verholpen in Fortinet FortiMail","original_title":"Kwetsbaarheid verholpen in Fortinet FortiMail","source_rating":null,"summary":"Fortinet heeft een kwetsbaarheid verholpen in FortiMail. FortiMail bevat een kritieke kwetsbaarheid (CVE-2026-104286) in de verwerking van bestandspaden, veroorzaakt door een combinatie van Path Traversal (CWE-22) en onvoldoende neutralisatie van NULL-bytes (CWE-158). Een niet-geauthenticeerde aanvaller kan via speciaa","ai":false,"actions":[],"url":"https://advisories.ncsc.nl/advisory?id=NCSC-2026-0398","type":"advisory","language":"nl","published_at":"2026-10-02T07:21:47+00:00","severity":"kritiek","priority":70,"vendors":["Fortinet"],"cves":[{"id":"CVE-2026-104286","cvss":9.8,"epss":0.02201,"epss_percentile":0.81912,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.8,"epss_max":0.02201,"source_count":2,"ncsc":{"kans":"M","schade":"H"},"source":{"slug":"ncsc-nl-advisories","name":"NCSC-NL Security Advisories","category":"overheid","country":"NL","license":"CC0 (Rijksoverheid)","reuse":"open"},"bundle":null},{"id":580,"title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","original_title":"CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability","source_rating":null,"summary":"Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.\n\nVereiste actie: Apply mitigations in accordance with vendor instructi","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104286","type":"kev","language":"en","published_at":"2026-10-01T00:00:00+00:00","severity":"hoog","priority":55,"vendors":["Fortinet"],"cves":[{"id":"CVE-2026-104286","cvss":9.8,"epss":0.02201,"epss_percentile":0.81912,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.8,"epss_max":0.02201,"source_count":2,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null},{"id":162,"title":"CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability","original_title":"CVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability","source_rating":null,"summary":"Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.\n\nVereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prio","ai":false,"actions":[],"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-25249","type":"kev","language":"en","published_at":"2026-09-09T00:00:00+00:00","severity":"hoog","priority":55,"vendors":["Fortinet"],"cves":[{"id":"CVE-2025-25249","cvss":9.8,"epss":0.03859,"epss_percentile":0.89853,"in_kev":true,"kev_ransomware":false}],"cve_count":1,"in_kev":true,"exploited_by":["CISA KEV","ENISA EUVD"],"kev_ransomware":false,"cvss_max":9.8,"epss_max":0.03859,"source_count":1,"ncsc":null,"source":{"slug":"cisa-kev","name":"CISA Known Exploited Vulnerabilities","category":"vulnerability","country":"US","license":"Publiek domein (US-overheid)","reuse":"open"},"bundle":null},{"id":286,"title":"Arbitrary process termination from exposed minifilter communication port","original_title":"Arbitrary process termination from exposed minifilter communication port","source_rating":null,"summary":"CVSSv3 Score: 4.7 An Unverified Ownership Vulnerability [CWE-283] in FortiClient Windows fortimon3 driver may allow an authenticated attacker to terminate arbitrary processes via an exposed…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-165","type":"advisory","language":"en","published_at":"2026-09-08T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Microsoft","Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":294,"title":"Uncontrolled Resource Consumption in SNMP","original_title":"Uncontrolled Resource Consumption in SNMP","source_rating":null,"summary":"CVSSv3 Score: 5.9 A Use of Uninitialized Variable [CWE-457] vulnerability in Fortinet FortiAnalyzer SNMP daemon may allow a remote authenticated attacker with user permission to cause a denial of…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-172","type":"advisory","language":"en","published_at":"2026-09-08T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":291,"title":"Null Pointer Dereference in Log Report","original_title":"Null Pointer Dereference in Log Report","source_rating":null,"summary":"CVSSv3 Score: 2.5 A NULL Pointer Dereference vulnerability [CWE-476] in FortiOS, FortiProxy and FortiPAM may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests.…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-173","type":"advisory","language":"en","published_at":"2026-09-08T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":292,"title":"Open Redirect on FortiSIEM","original_title":"Open Redirect on FortiSIEM","source_rating":null,"summary":"CVSSv3 Score: 2.8 An URL redirection to untrusted site ('open redirect') [CWE-601] vulnerability in FortiSIEM may allow an authenticated attacker to cause a redirection to any website via specially…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-169","type":"advisory","language":"en","published_at":"2026-09-08T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":289,"title":"Improper Authentication of FortiPAM Server","original_title":"Improper Authentication of FortiPAM Server","source_rating":null,"summary":"CVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-168","type":"advisory","language":"en","published_at":"2026-09-08T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet","Google"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":296,"title":"ZTNA Portal Improper Certificate Validation","original_title":"ZTNA Portal Improper Certificate Validation","source_rating":null,"summary":"CVSSv3 Score: 7.3 An improper certificate validation vulnerability [CWE-295] in FortiOS and FortiProxy Agentless ZTNA portal may allow a remote and unauthenticated attacker to perform a…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-174","type":"advisory","language":"en","published_at":"2026-09-08T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":295,"title":"Workflow session email approval process bypass","original_title":"Workflow session email approval process bypass","source_rating":null,"summary":"CVSSv3 Score: 4.7 An improper access control vulnerability [CWE-284] in FortiManager may allow an administrator to bypass the approval process for workflow sessions via crafted HTTP or HTTPs…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-171","type":"advisory","language":"en","published_at":"2026-09-08T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":304,"title":"UI DoS attack","original_title":"UI DoS attack","source_rating":null,"summary":"CVSSv3 Score: 5.0 An Allocation of Resources Without Limits or Throttling vulnerability [CWE-770] in FortiOS may allow an unauthenticated attacker to perform a slow HTTP DoS attack on the web…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-162","type":"advisory","language":"en","published_at":"2026-08-12T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":300,"title":"FGFM Authentication Weakening via CLI Configuration","original_title":"FGFM Authentication Weakening via CLI Configuration","source_rating":null,"summary":"CVSSv3 Score: 7.3 An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-160","type":"advisory","language":"en","published_at":"2026-08-12T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":302,"title":"Server-Side Request Forgery (SSRF)","original_title":"Server-Side Request Forgery (SSRF)","source_rating":null,"summary":"CVSSv3 Score: 3.4 A Server-Side request forgery (SSRF) [CWE-918] vulnerability in FortiSIEM GUI may allow an authenticated attacker to send HTTP requests originating from the targeted device via…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-159","type":"advisory","language":"en","published_at":"2026-08-12T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":301,"title":"Heap overflow in kernel driver due to missing size validation","original_title":"Heap overflow in kernel driver due to missing size validation","source_rating":null,"summary":"CVSSv3 Score: 7.3 A buffer copy without checking size of input vulnerability [CWE-120] in FortiClient Windows may allow an unauthenticated attacker in a position to alter or craft DNS responses to…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-156","type":"advisory","language":"en","published_at":"2026-08-12T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Microsoft","Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":303,"title":"Stack buffer overflow in WAD","original_title":"Stack buffer overflow in WAD","source_rating":null,"summary":"CVSSv3 Score: 5.1 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS explicit proxy may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-161","type":"advisory","language":"en","published_at":"2026-08-12T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":299,"title":"Content-Encoding WAF Evasion","original_title":"Content-Encoding WAF Evasion","source_rating":null,"summary":"CVSSv3 Score: 4.8 An incomplete list of disallowed inputs [CWE-184] in FortiWeb WAF may allow an unauthenticated attacker to bypass policies via specifically crafted requests. Revised on 2026-08-12…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-157","type":"advisory","language":"en","published_at":"2026-08-12T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":298,"title":"Broken access control in the RADIUS type admin group","original_title":"Broken access control in the RADIUS type admin group","source_rating":null,"summary":"CVSSv3 Score: 8.8 An Improper Authentication vulnerability [CWE-287] in the FortiWeb Remote Radius Type Admin Authentication configured with specific, non-default settings may allow a remote…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-158","type":"advisory","language":"en","published_at":"2026-08-12T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":312,"title":"SSL-VPN Reflected XSS","original_title":"SSL-VPN Reflected XSS","source_rating":null,"summary":"CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-150","type":"advisory","language":"en","published_at":"2026-07-14T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":313,"title":"Stack Buffer Overflow in Log Report","original_title":"Stack Buffer Overflow in Log Report","source_rating":null,"summary":"CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-148","type":"advisory","language":"en","published_at":"2026-07-14T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":305,"title":"Buffer overread in authd and wad daemon","original_title":"Buffer overread in authd and wad daemon","source_rating":null,"summary":"CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-154","type":"advisory","language":"en","published_at":"2026-07-14T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":314,"title":"Supers override fails to properly override supervisor address","original_title":"Supers override fails to properly override supervisor address","source_rating":null,"summary":"CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-155","type":"advisory","language":"en","published_at":"2026-07-14T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Microsoft","Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":311,"title":"Path traversal in CLI command allows deletion of root file system","original_title":"Path traversal in CLI command allows deletion of root file system","source_rating":null,"summary":"CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-151","type":"advisory","language":"en","published_at":"2026-07-14T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":309,"title":"Missed certificate verification in AD Connector communication with FortiClient EMS","original_title":"Missed certificate verification in AD Connector communication with FortiClient EMS","source_rating":null,"summary":"CVSSv3 Score: 6.7 An Improper Certificate Validation vulnerability [CWE-295] in FortiClient EMS may allow a remote unauthenticated attacker to impersonate an AD Connector via a valid API Key.…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-147","type":"advisory","language":"en","published_at":"2026-07-14T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":308,"title":"Header injection in captive portal authentication form","original_title":"Header injection in captive portal authentication form","source_rating":null,"summary":"CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-153","type":"advisory","language":"en","published_at":"2026-07-14T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":307,"title":"Header injection in Web Filter warning page","original_title":"Header injection in Web Filter warning page","source_rating":null,"summary":"CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-152","type":"advisory","language":"en","published_at":"2026-07-14T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":306,"title":"Cross-Site Scripting in Domain parameter","original_title":"Cross-Site Scripting in Domain parameter","source_rating":null,"summary":"CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-149","type":"advisory","language":"en","published_at":"2026-07-14T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null},{"id":514,"title":"Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways","original_title":"Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways","source_rating":null,"summary":"Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.","ai":false,"actions":[],"url":"https://www.ncsc.gov.uk/news/advice-following-global-targeting-of-fortinet-firewalls-and-vpn-gateways","type":"news","language":"en","published_at":"2026-06-18T12:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"ncsc-uk","name":"NCSC-UK News","category":"overheid","country":"UK","license":"© Crown copyright","reuse":"excerpt"},"bundle":null},{"id":317,"title":"Restricted CLI escape using Lua","original_title":"Restricted CLI escape using Lua","source_rating":null,"summary":"CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via…","ai":false,"actions":[],"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-143","type":"advisory","language":"en","published_at":"2026-06-09T07:00:00+00:00","severity":"laag","priority":0,"vendors":["Fortinet"],"cves":[],"cve_count":0,"in_kev":false,"exploited_by":[],"kev_ransomware":false,"cvss_max":null,"epss_max":null,"source_count":1,"ncsc":null,"source":{"slug":"fortinet-psirt","name":"Fortinet PSIRT","category":"vendor","country":null,"license":"© Fortinet","reuse":"excerpt"},"bundle":null}]}