Vulnerabilities · 5h ago

Fortinet FortiMail path traversal is actively exploited

Fortinet and CISA say CVE-2026-104286, a critical path-traversal flaw in FortiMail, is being actively exploited against exposed mail gateways. The issue affects FortiMail 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9.

A crafted HTTP or HTTPS request can make the appliance step outside its intended folder structure, letting an unauthenticated attacker write arbitrary files and potentially turn that into code or command execution. Because the target is a mail gateway, compromise lands on the appliance itself, not just one mailbox, and can put mail flow and policy enforcement at risk.

The fix is uneven across branches: FortiMail 7.2 does not get an in-branch backport, so operators there have to plan a move to 7.4.9 or later. For internet-facing deployments, the exposure persists wherever the gateway remains reachable and unupdated.

CVE-2026-104286

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail…

CISA federal remediation date Oct 4 · date passed

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Fortinet

Part of the PlainSec briefing for 2026-10-08

Editions

Related stories