Exploited Vulnerabilities Daily
🌐 한국어

← 전체 신규 항목

CVE-2026-104286: Fortinet FortiMail

Fortinet FortiMail에는 NULL byte 또는 NULL 문자 취약점의 경로 트레이널 및 임퍼 중립화가 포함되어있어 의도적 인 공격자를 허용 할 수 있습니다 기술 HTTP 또는 HTTPS 요청을 통해 underlying 시스템에서 임의 파일을 작성 할 수 있습니다.

CISA (English)

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

공급업체
Fortinet
제품
FortiMail
취약점
Fortinet FortiMail Path Traversal Vulnerability
추가일
2026. 10. 1.
CISA 조치 기한(미국 연방기관)
2026. 10. 4.
랜섬웨어 공격 악용
알 수 없음
약점(CWE)
CWE-22, CWE-158

참고 자료

이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.

최종 업데이트: · 카탈로그 버전 2026.10.02