## Overview
CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) list on October 1, 2026. This vulnerability impacts Fortinet FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. It allows unauthenticated attackers to exploit path traversal issues and write arbitrary files on the underlying system.
## Technical Details
The vulnerability arises from an improper limitation of a pathname to a restricted directory. Attackers can send crafted HTTP or HTTPS requests to manipulate the file system. This exploitation can occur without authentication, making it particularly dangerous. The CVSS score of 9.8 reflects its severity. Evidence of exploitation has been observed, prompting CISA's swift action.
## Impact
Successful exploitation of this vulnerability can lead to unauthorized file writes on the server. This could compromise the integrity of the system, allow for data exfiltration, or facilitate further attacks. Organizations using affected versions of FortiMail are at risk of significant security breaches.
## Mitigation
Fortinet has released patches for the affected versions. Organizations should immediately update FortiMail to the latest version to mitigate this vulnerability. Regularly review security configurations and monitor for unusual activity. Implementing web application firewalls can also help in detecting and blocking malicious requests.
CSURFACE Threat Sensor