HIGHVulnerability
Verified
Global
CISA KEV: Fortinet FortiMail — Fortinet FortiMail Path Traversal Vulnerability
·Source: CISA KEV
Updated:
Executive Summary
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Analysis
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Added to CISA Known Exploited Vulnerabilities catalog on 2026-10-01. Remediation due: 2026-10-04.