CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability

Summary

Fortinet FortiMail is vulnerable to a path traversal and improper neutralization of NULL byte flaw, allowing unauthenticated attackers to write arbitrary files to the system via crafted HTTP/HTTPS requests. CISA has mandated mitigations and a federal patching deadline of October 4, 2026.

IFF Assessment

FOE

This vulnerability allows attackers to write arbitrary files to the system, which could lead to further compromise and exploitation.

Severity

8.8 High (AI Estimated)

The CVSS score of 8.8 (High) reflects the potential for an unauthenticated attacker to write arbitrary files to the system, which can lead to remote code execution or significant system compromise. The attack vector is Network, and the impact on Confidentiality, Integrity, and Availability is High.

CISA KEV: Listed as actively exploited. Federal patch due: October 04, 2026. Known ransomware use: Unknown.

Defender Context

Defenders should prioritize patching or mitigating this vulnerability in Fortinet FortiMail devices, especially those exposed to the internet. The ability to write arbitrary files can be a precursor to full system takeover, including ransomware deployment or data exfiltration.

Read Full Story →