RaqibCTI
CVE

CVE-2026-104286

P2
Fortinet FortiMail Path Traversal Vulnerability
Fortinet · FortiMail
Date added (CISA)
2026-10-01
Remediation due
2026-10-04
Known ransomware use
Not indicated
Remediation priority
P2 — CISA due date imminent

Description

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Source: NVD ↗ · CISA KEV Catalog ↗