CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-10-01. EPSS: 2.2% chance of exploitation in the next 30 days.
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Affected products
- Fortinet FortiMail: from 7.2.0, up to and including 7.4.8; from 7.6.0, up to and including 7.6.6; from 8.0.0, up to and including 8.0.1
Published 2026-10-01. Last modified 2026-10-07.