CVE-2026-104286: listed in the CISA KEV catalog CVE-2026-104286 · CVSS 9.8 CRITICAL · KEV 2026-10-01 · patch available
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Is CVE-2026-104286 exploited? Listed in the CISA KEV catalog on 2026-10-01. Federal remediation due 2026-10-04. Public exploit code: none found in monitored sources. Which products and versions are affected? Fortinet · FortiMail · <7.4.9 Fortinet · FortiMail · <7.6.7 Fortinet · FortiMail · <8.0.2 Fortinet · FortiMail · 8.0.0, 7.6.0 - 7.6.5, 7.4.0 - 7.4.6, 7.2.0 - 7.2.9, 7.0.0 - 7.0.9 Is there a patch? FortiMail 7.4.9 FortiMail 7.6.7 FortiMail 8.0.2 What PlainSec published about CVE-2026-104286 Primary sources What this record does not say KEV and EPSS are re-checked daily. Record last updated 2026-10-02.
CVE-2026-104286: listed in the CISA KEV catalog CVE-2026-104286 · CVSS 9.8 CRITICAL · KEV 2026-10-01 · patch available
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Is CVE-2026-104286 exploited? Listed in the CISA KEV catalog on 2026-10-01. Federal remediation due 2026-10-04. Public exploit code: none found in monitored sources. Which products and versions are affected? Fortinet · FortiMail · <7.4.9 Fortinet · FortiMail · <7.6.7 Fortinet · FortiMail · <8.0.2 Fortinet · FortiMail · 8.0.0, 7.6.0 - 7.6.5, 7.4.0 - 7.4.6, 7.2.0 - 7.2.9, 7.0.0 - 7.0.9 Is there a patch? FortiMail 7.4.9 FortiMail 7.6.7 FortiMail 8.0.2 What PlainSec published about CVE-2026-104286 Primary sources What this record does not say KEV and EPSS are re-checked daily. Record last updated 2026-10-02.