CVE-2026-104286: presente nel catalogo CISA KEV CVE-2026-104286 · CVSS 9.8 CRITICAL · KEV 2026-10-01 · patch disponibile
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
CVE-2026-104286 viene sfruttato? Inserito nel catalogo CISA KEV il 2026-10-01. Scadenza di remediation federale: 2026-10-04. Codice di exploit pubblico: nessuno trovato nelle fonti monitorate. Quali prodotti e versioni sono interessati? Fortinet · FortiMail · <7.4.9 Fortinet · FortiMail · <7.6.7 Fortinet · FortiMail · <8.0.2 Fortinet · FortiMail · 8.0.0, 7.6.0 - 7.6.5, 7.4.0 - 7.4.6, 7.2.0 - 7.2.9, 7.0.0 - 7.0.9 Esiste una patch? FortiMail 7.4.9 FortiMail 7.6.7 FortiMail 8.0.2 Cosa ha pubblicato PlainSec su CVE-2026-104286 Fonti primarie Cosa questa scheda non dice KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-10-02.
CVE-2026-104286: presente nel catalogo CISA KEV CVE-2026-104286 · CVSS 9.8 CRITICAL · KEV 2026-10-01 · patch disponibile
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
CVE-2026-104286 viene sfruttato? Inserito nel catalogo CISA KEV il 2026-10-01. Scadenza di remediation federale: 2026-10-04. Codice di exploit pubblico: nessuno trovato nelle fonti monitorate. Quali prodotti e versioni sono interessati? Fortinet · FortiMail · <7.4.9 Fortinet · FortiMail · <7.6.7 Fortinet · FortiMail · <8.0.2 Fortinet · FortiMail · 8.0.0, 7.6.0 - 7.6.5, 7.4.0 - 7.4.6, 7.2.0 - 7.2.9, 7.0.0 - 7.0.9 Esiste una patch? FortiMail 7.4.9 FortiMail 7.6.7 FortiMail 8.0.2 Cosa ha pubblicato PlainSec su CVE-2026-104286 Fonti primarie Cosa questa scheda non dice KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-10-02.