CVE-2021-36166: Fortinet FortiMail

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties.

Affected products

  • Fortinet FortiMail: up to and including 5.4.12; from 6.0.0, before 6.0.12 (fixed in 6.0.12); from 6.2.0, before 6.2.8 (fixed in 6.2.8); from 6.4.0, before 6.4.6 (fixed in 6.4.6); version 7.0.0 only

Published 2022-03-01. Last modified 2026-06-17.