CVE-2026-104286: FortiMail Path Traversal Vulnerability Actively Exploited
Brief
Successful exploitation may let an unauthenticated attacker send a crafted request that tricks FortiMail into writing a file outside its intended folder.
By placing a file onto the underlying system, the attacker gains a way to run commands on the device itself. This can lead to full control of the mail gateway, exposing stored mail, credentials, and other systems it connects to.
CVE
CVE-2026-104286
Affected Products
FortiMail 8. 0 through 8.
- 1 FortiMail 7. 6 through 7.
- 6 FortiMail 7. 4 through 7.
- 8 FortiMail 7. 2 through 7.
- 9
Exploitation
The vulnerability has been exploited in the wild[1].
