high Known exploited

CVE-2026-104286

Fortinet FortiMail Path Traversal Vulnerability

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Published
Oct 1, 2026
CVSS
9.8
Vendor
Fortinet
Product
FortiMail
CISA due date
2026-10-04
Source
merged

References

Check your website: Korisec scans for exposed services, weak TLS, missing headers, and WordPress plugin risks. Run a free scan or start a trial.

← Back to CVE Tracker · Official record: cve.org