Planet Briefing

First published · Last updated

CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability

Fortinet FortiMail contains a path traversal and NULL-byte vulnerability that may allow an unauthenticated attacker to write arbitrary files via crafted HTTP or HTTPS requests. The source directs stakeholders to apply vendor mitigations and follow CISA BOD 26-04 and forensics triage guidance, or discontinue product use if mitigations are unavailable.

Distinctive ice cream stand outside Computer Museum and Children's Museum, Boston, Massachusetts
Illustrative image: Distinctive ice cream stand outside Computer Museum and Children's Museum, Boston, Massachusetts — Highsmith, Carol M., 1946-/Library of Congress, Free to Use and Reuse

Categories: technology

Generated scores

Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.

Confidence
6/10
Geographic reach
1/10
Global importance
3/10
Impact magnitude
4/10
Positivity
2/10
Urgency
6/10

Why it matters

May allow unauthenticated attackers to write arbitrary files on affected systems, so organizations must implement the vendor and CISA mitigation guidance.

Location

Sources

Report an issue