2026年10月2日星期五

Fortinet 產品遠端執行程式碼漏洞

Fortinet 產品遠端執行程式碼漏洞

發佈日期: 2026年10月02日

於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及資料篡改。

 

注意:

CVE-2025-25249 正在被廣泛利用。此漏洞涉及未有適當限制受限目錄的路徑名稱(「路徑遍歷」),以及未有妥善處理 NULL 位元組或 NULL 字元。未經身份驗證的攻擊者可透過特製的 HTTP 或 HTTPS 請求,在底層系統上寫入任意檔案。因此,該漏洞的風險等級被評為極高度風險。


影響

  • 遠端執行程式碼
  • 篡改

受影響之系統或技術

FortiMail

  • FortiMail 8.0.0 至 8.0.1
  • FortiMail 7.6.0 至 7.6.6
  • FortiMail 7.4.0 至 7.4.8
  • FortiMail 7.2.0 至 7.2.9

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

 


Fortinet Products Remote Code Execution Vulnerability

Fortinet Products Remote Code Execution Vulnerability

Release Date: 2 Oct 2026

Multiple vulnerabilities were identified in Fortinet Products. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution and data manipulation on the targeted system.

 

Note:

CVE-2025-25249 is being exploited in the wild. An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') and Improper Neutralization of NULL Byte or NULL Character vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Hence, the risk level of this vulnerability is rated as Extremely High Risk.


Impact

  • Remote Code Execution
  • Data Manipulation

System / Technologies affected

FortiMail

  • FortiMail 8.0.0 through 8.0.1
  • FortiMail 7.6.0 through 7.6.6
  • FortiMail 7.4.0 through 7.4.8
  • FortiMail 7.2.0 through 7.2.9

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


Mozilla Thunderbird 多個漏洞

Mozilla Thunderbird 多個漏洞

發佈日期: 2026年10月02日

於 Mozilla 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼、資料篡改及彷冒。


影響

  • 遠端執行程式碼
  • 阻斷服務
  • 權限提升
  • 繞過保安限制
  • 資料洩露
  • 篡改
  • 仿冒

受影響之系統或技術

以下版本之前的版本﹕

 

  • Thunderbird 140.17
  • Thunderbird 153.4
  • Thunderbird 157

解決方案

在安裝軟體之前,請先瀏覽供應商之官方網站,以獲得更多詳細資料。

更新至版本:

 

  • Thunderbird 140.17
  • Thunderbird 153.4
  • Thunderbird 157

漏洞識別碼


資料來源


相關連結

 


Mozilla Thunderbird Multiple Vulnerabilities

Mozilla Thunderbird Multiple Vulnerabilities

Release Date: 2 Oct 2026

Multiple vulnerabilities were identified in Mozilla Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution, data manipulation and spoofing on the targeted system.


Impact

  • Remote Code Execution
  • Denial of Service
  • Elevation of Privilege
  • Security Restriction Bypass
  • Information Disclosure
  • Data Manipulation
  • Spoofing

System / Technologies affected

Versions prior to:

 

  • Thunderbird 140.17
  • Thunderbird 153.4
  • Thunderbird 157

Solutions

Before installation of the software, please visit the vendor web-site for more details.

Apply fixes issued by the vendor:

 

  • Thunderbird 140.17
  • Thunderbird 153.4
  • Thunderbird 157

Vulnerability Identifier


Source


Related Link

 


SUSE Linux 內核多個漏洞

SUSE Linux 內核多個漏洞

發佈日期: 2026年10月02日

於 SUSE Linux 內核 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升、繞過保安限制及敏感資料洩露。


影響

  • 權限提升
  • 資料洩露
  • 繞過保安限制

受影響之系統或技術

  • SUSE Linux Enterprise Live Patching 15-SP7
  • SUSE Linux Enterprise Real Time 15 SP7
  • SUSE Linux Enterprise Server 15 SP7
  • SUSE Linux Enterprise Server 16.0
  • SUSE Linux Enterprise Server for SAP Applications 15 SP7
  • SUSE Linux Enterprise Server for SAP applications 16.0
  • SUSE Linux Micro 6.2

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

 


SUSE Linux Kernel Multiple Vulnerabilities

SUSE Linux Kernel Multiple Vulnerabilities

Release Date: 2 Oct 2026

Multiple vulnerabilities were identified in SUSE Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, security restriction bypass and sensitive information disclosure on the targeted system.


Impact

  • Elevation of Privilege
  • Information Disclosure
  • Security Restriction Bypass

System / Technologies affected

  • SUSE Linux Enterprise Live Patching 15-SP7
  • SUSE Linux Enterprise Real Time 15 SP7
  • SUSE Linux Enterprise Server 15 SP7
  • SUSE Linux Enterprise Server 16.0
  • SUSE Linux Enterprise Server for SAP Applications 15 SP7
  • SUSE Linux Enterprise Server for SAP applications 16.0
  • SUSE Linux Micro 6.2

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

 


Debian Linux 內核多個漏洞

Debian Linux 內核多個漏洞

發佈日期: 2026年10月02日

於 Debian Linux 內核發現多個漏洞。遠遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升及敏感資料洩露。


影響

  • 阻斷服務
  • 資料洩露
  • 權限提升

受影響之系統或技術

  • Debian stable distribution (trixie) 6.12.111-1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

 


Fortinet 產品遠端執行程式碼漏洞

Fortinet 產品遠端執行程式碼漏洞 發佈日期 : 2026 年 10 月 02 日 於 Fortinet 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行任意程式碼及資料篡改。   注意: CVE-2025-25249 正在被廣泛利用...