HIGHVulnerability
Verified
Global

CISA KEV: Fortinet FortiMail — Fortinet FortiMail Path Traversal Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Analysis

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Added to CISA Known Exploited Vulnerabilities catalog on 2026-10-01. Remediation due: 2026-10-04.

Indicators of Compromise (1)

CVE (1)
CVE-2026-104286
Source Attribution

Originally published by CISA KEV on Oct 1, 2026. Verified by: CISA.

Related Threats