OCTOBER 3, 2026
Live Feed
Back to database
Case File

CVE-2026-104286

CRITICAL · CVSS 9.8 EPSS 1.78%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-03

CyberRota Analysis

AI-Generated

Fortinet FortiMail versions 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9 are vulnerable to a path traversal flaw that enables unauthenticated attackers to write arbitrary files on the system through specially crafted HTTP or HTTPS requests. This critical vulnerability (CVSS 9.8) poses a significant risk of unauthorized access and potential system compromise. Organizations using affected FortiMail versions should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-104286
Severity
CRITICAL
CVSS
9.8
EPSS
1.78%
Fortinet

Original NVD Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Related CVEs

Other vulnerabilities affecting the same vendor(s)