CVE-2026-104286 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 1.8% (pctl 77)
Patch first
On CISA KEV — known exploited in the wild, due 2026-10-04.
Description
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.78% — more likely to be exploited than 77% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | yes — remediate by 2026-10-04 |
| Public exploit | none known |
| Published | 2026-10-01 |
| Last modified | 2026-10-02 |
CISA KEV
| Name | Fortinet FortiMail Path Traversal Vulnerability |
|---|---|
| Added | 2026-10-01 |
| Due | 2026-10-04 |
| Vendor / product | Fortinet / FortiMail |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| fortinet | fortimail |
References
→ the Explorer · watch your stack · NVD