Fortinet Products Remote Code Execution Vulnerability
Release Date: 2 Oct 2026
Multiple vulnerabilities were identified in Fortinet
Products. A remote attacker could exploit some of these vulnerabilities to
trigger remote code execution and data manipulation on the targeted system.
Note:
CVE-2025-25249 is being exploited in the wild. An
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
and Improper Neutralization of NULL Byte or NULL Character vulnerability may
allow an unauthenticated attacker to write arbitrary files on the underlying
system via crafted HTTP or HTTPS requests. Hence, the risk level of
this vulnerability is rated as Extremely High Risk.
Impact
- Remote
Code Execution
- Data
Manipulation
System / Technologies affected
FortiMail
- FortiMail
8.0.0 through 8.0.1
- FortiMail
7.6.0 through 7.6.6
- FortiMail
7.4.0 through 7.4.8
- FortiMail
7.2.0 through 7.2.9
Solutions
Before installation of the software, please visit the
vendor web-site for more details.
Apply fixes issued by the vendor:
Vulnerability Identifier
Source
Related Link
- https://fortiguard.fortinet.com/psirt/FG-IR-26-175
- https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
沒有留言:
發佈留言