NCSC-2026-0015 [1.01] [M/H] Kwetsbaarheid verholpen in Fortinet FortiOS
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Fortinet heeft een kwetsbaarheid verholpen in FortiOS (Specifiek voor FortiSASE en FortiSwitchManager). De kwetsbaarheid bevindt zich in de cw_acd daemon in FortiOS en FortiSwitchManager. Deze daemon is kwetsbaar voor exploitatie door externe, niet-geauthenticeerde aanvallers. Door het verzenden van speciaal vervaardigde pakketten of verzoeken, kunnen aanvallers willekeurige code of commando's op de getroffen systemen uitvoeren. UPDATE Het Amerikaanse CISA heeft op 9 september de kwetsbaarheid op de Known Exploited Vulnerabilities-catalogus geplaatst. Organisaties wordt geadviseerd de updates van Fortinet direct toe te passen en kwetsbare, extern bereikbare systemen te controleren op aanwijzingen van misbruik. EINDE UPDATE
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0015
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2025-25249Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 76% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-25249 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[UPDATE] [hoch] Fortinet FortiOS: Schwachstelle ermöglicht Codeausführungcert-bund
- criticalexploitedFortinet security advisory (AV26-023) - Update 1cccs
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2025-25249: Fortinet Multiple Products Heap-based Buffer Overflow Vulnerabilitycisa-kev
Recent advisories for Kwetsbaarheid verholpen in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0359 [1.00] [M/H] Kwetsbaarheid verholpen in Ivanti Endpoint Manager Mobilencsc-nl · 2026-09-09
- unknownNCSC-2026-0357 [1.00] [M/H] Kwetsbaarheid verholpen in Ivanti Sentryncsc-nl · 2026-09-09
- unknownexploitedNCSC-2026-0354 [1.00] [M/H] Kwetsbaarheid verholpen in Google Chromencsc-nl · 2026-09-09
- unknownexploitedNCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magentoncsc-nl · 2026-09-08
- unknownexploitedNCSC-2026-0342 [1.00] [H/H] Kwetsbaarheid verholpen in N-central van N-ablencsc-nl · 2026-09-07
- unknownexploitedNCSC-2026-0336 [1.00] [M/H] Kwetsbaarheid verholpen in JFrog Artifactoryncsc-nl · 2026-09-02
More from NCSC-NL Advisories
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion2026-09-09
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commerce2026-09-09