Junglewise Threat Intelligence

CVE-2026-104286: Fortinet FortiMail path traversal vulnerability

CVE-2026-104286 · Severity: critical · Exploited in the wild · Published 2026-10-01

Vendors: Fortinet.

Executive brief

Fortinet FortiMail is an email security appliance that protects organizations from email-borne threats. An unauthenticated attacker can exploit a path traversal vulnerability to write arbitrary files to the system, potentially leading to complete system compromise, data theft, or service disruption.

Technical details

FortiMail contains a path traversal and NULL byte/character neutralization vulnerability in its HTTP/HTTPS request handling. An unauthenticated attacker can craft malicious requests to write arbitrary files to the underlying system, bypassing access controls and file path restrictions.

Affected products

  • Fortinet FortiMail <UNKNOWN>

Timeline

  • 2026-10-01: disclosed
  • 2026-10-01: exploited: Reported exploited in wild

Related threats