CVE-2026-104286
published 2026-10-01CVE-2026-104286: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0…
PriorityP195critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-10-04
Exploited in the wild
EPSS
2.20%
81.9th percentile
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimail | — | — |
| fortinet | fortimail | — | — |
| fortinet | fortimail | 7.0.0 – 7.0.9 | — |
| fortinet | fortimail | 7.2.0 – 7.4.8 | — |
| fortinet | fortimail | 7.4.0 – 7.4.6 | — |
| fortinet | fortimail | 7.6.0 – 7.6.6 | — |
| fortinet | fortimail | 8.0.0 – 8.0.1 | — |
| fortinet | fortinet | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8,
ghsa_unreviewed·2026-10-01
CVE-2026-104286 [CRITICAL] CWE-22 An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8,
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
VulDB
Fortinet FortiMail up to 7.2.9/7.4.8/7.6.6/8.0.1 path traversal
vuldb·2026-10-01·CVSS 9.8
CVE-2026-104286 [CRITICAL] Fortinet FortiMail up to 7.2.9/7.4.8/7.6.6/8.0.1 path traversal
A vulnerability, which was classified as very critical, has been found in Fortinet FortiMail up to 7.2.9/7.4.8/7.6.6/8.0.1. This affects an unknown part. This manipulation causes path traversal.
This vulnerability is tracked as CVE-2026-104286. The attack is possible to be carried out remotely. Moreover, an exploit is present.
VulnCheck
Fortinet FortiMail Path Traversal Vulnerability
vulncheck·2026·CVSS 9.8
CVE-2026-104286 [CRITICAL] CWE-22 Fortinet FortiMail Path Traversal Vulnerability
Fortinet FortiMail Path Traversal Vulnerability
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Affected: Fortinet FortiMail
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherenc
Fortinet
Improper limitation of a pathname to a restricted directory
vendor_fortinet·2026-10-01·CVSS 9.8
CVE-2026-104286 [CRITICAL] CWE-22 Improper limitation of a pathname to a restricted directory
FG-IR-26-175: Improper limitation of a pathname to a restricted directory
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
CVEs: CVE-2026-104286
CWEs: CWE-22
CVSS: 9.8 (critical)
Affected products: FortiMail, Fortinet
CISA
Fortinet FortiMail Path Traversal Vulnerability
cisa·2026-10-01·CVSS 9.8
CVE-2026-104286 [CRITICAL] CWE-22 Fortinet FortiMail Path Traversal Vulnerability
Vulnerability: Fortinet FortiMail Path Traversal Vulnerability
Affected: Fortinet FortiMail
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ens
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
blogs_hackernews·2026-10-05·CVSS 7.5
CVE-2026-88779 [HIGH] ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook.
There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others are still getting in because the basics gave way first.
Here’s what mattered this week.
## ⚡ Threat of the Week
Citrix Warns of Ne
Hackernews
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
blogs_hackernews·2026-10-02·CVSS 9.8
CVE-2026-104286 [CRITICAL] Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.
The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system.
"An improper limitation of a pathname to a restricted directory ('path traversal') [CWE-22] and improper neutralization of NULL byte or NULL chara
2026-10-01
Published
2026-10-01
Added to CISA KEV
Exploited in the wild