CVE-2026-104286

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

  • Published Oct 1, 2026
  • CVSS 9.8 critical
  • 2.2% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog

Affected software

In the news

CVE-2026-104286 at the National Vulnerability Database