Executive brief
Fortinet FortiMail is an email security appliance that protects organizations from email-borne threats. An unauthenticated attacker can exploit a path traversal vulnerability to write arbitrary files to the system, potentially leading to complete system compromise, data theft, or service disruption.
Technical details
FortiMail contains a path traversal and NULL byte/character neutralization vulnerability in its HTTP/HTTPS request handling. An unauthenticated attacker can craft malicious requests to write arbitrary files to the underlying system, bypassing access controls and file path restrictions.
Affected products
- Fortinet FortiMail <UNKNOWN>
Timeline
- 2026-10-01: disclosed
- 2026-10-01: exploited: Reported exploited in wild