CVE-2026-104286
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
- Published Oct 1, 2026
- CVSS 9.8 critical
- 2.2% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
Affected software
In the news
- ⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests The Hacker News ·
- A Vulnerability in Fortinet FortiMail Could Allow for Arbitrary Code Execution CIS MS-ISAC ·
- Fortinet security advisory (AV26-989) Canadian Centre for Cyber Security ·
- Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) Help Net Security ·
- Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action SecurityWeek ·
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes The Hacker News ·
- Vulnerability in Fortinet FortiMail CERT-FR ·
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks BleepingComputer ·
- CISA Adds One Known Exploited Vulnerability to Catalog CISA ·