peter bassill · operator
$ cve CVE-2026-104286 JSON

CVE-2026-104286 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 1.8% (pctl 77)

Patch first

On CISA KEV — known exploited in the wild, due 2026-10-04.

Description

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.78% — more likely to be exploited than 77% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2026-10-04
Public exploitnone known
Published2026-10-01
Last modified2026-10-02

CISA KEV

NameFortinet FortiMail Path Traversal Vulnerability
Added2026-10-01
Due2026-10-04
Vendor / productFortinet / FortiMail
Ransomware usenone reported

Affected (1)

VendorProduct
fortinetfortimail

References

→ the Explorer  ·  watch your stack  ·  NVD