CVE-2026-104286: Fortinet FortiMail
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
- Vendor
- Fortinet
- Product
- FortiMail
- Vulnerability
- Fortinet FortiMail Path Traversal Vulnerability
- Date added
- Oct 1, 2026
- CISA due date (U.S. federal agencies)
- Oct 4, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-22, CWE-158
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02