What is CVE-2026-104286?
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Timeline
- 2026-10-01Published to the U.S. National Vulnerability Database (NVD)
- 2026-10-01Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-10-02First covered in a defend.network daily briefing
- 2026-10-02NVD record last updated
- 2026-10-04CISA federal remediation deadline (BOD 22-01)
CISA Known Exploited Vulnerability
Fortinet FortiMail Path Traversal Vulnerability
Affected product
Fortinet FortiMail
Remediation Steps
- Apply the latest security patch from Fortinet immediately
- Restrict inbound access to FortiMail services to trusted networks if emergency patching is delayed
- Monitor FortiMail logs for suspicious command execution or unauthorized access attempts
- Review recent access logs to identify any successful exploitation
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of September 2026 (September 28 – October 4)
- Fortinet FortiMail zero-day exploited; KillSec ransomware leadership dismantled (2026-10-02)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.