Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2026-104286: Fortinet FortiMail

Fortinet FortiMail包含一個路徑轉錄和NULL位元組或NULL字元脆弱性的不當中性,可能讓一個未經認證的攻擊者透過精心設計的HTTP或HTTPs請求在基礎系統中寫入任意檔案。

CISA (English)

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

廠商
Fortinet
產品
FortiMail
漏洞
Fortinet FortiMail Path Traversal Vulnerability
加入日期
2026年10月1日
CISA 修補期限(美國聯邦機關)
2026年10月4日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-22, CWE-158

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02