CVE-2026-104286
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail…
CISA federal remediation date Oct 4 · date passed
Vulnerabilities & Exploits · Web App Attack
Fortinet and CISA say CVE-2026-104286, a critical path-traversal flaw in FortiMail, is being actively exploited against exposed mail gateways. The issue affects FortiMail 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9.
A crafted HTTP or HTTPS request can make the appliance step outside its intended folder structure, letting an unauthenticated attacker write arbitrary files and potentially turn that into code or command execution. Because the target is a mail gateway, compromise lands on the appliance itself, not just one mailbox, and can put mail flow and policy enforcement at risk.
The fix is uneven across branches: FortiMail 7.2 does not get an in-branch backport, so operators there have to plan a move to 7.4.9 or later. For internet-facing deployments, the exposure persists wherever the gateway remains reachable and unupdated.
1 source · 6h ago
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail…
CISA federal remediation date Oct 4 · date passed
INCIBE-CERT
Path Traversal en FortiMail de Fortinet
Fortinet ha publicado una vulnerabilidad de severidad crítica que, en caso de ser explotada, podría pe
originalPart of the PlainSec briefing for 2026-10-08
Every edition of this story: Fortinet FortiMail path traversal is actively exploited