CVE-2026-104286
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
- CVSS
- 9.8
- EPSS
- —
- CISA KEV
- Added 2026-10-01, due 2026-10-04
- Exploitation
- active
- Public exploits
- None seen
- State
- PUBLISHED
Coverage
Actively exploitedCritical 100BleepingComputerAuthoritative. Authoritative publisher: a primary source, or a newsroom with formal editorial standards
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]
Actively exploitedCritical 100CISA advisories & alertsAuthoritative. Authoritative publisher: a primary source, or a newsroom with formal editorial standards
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses…
What we observed
- kev addedcisa-kev