As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0398 [1.00] [M/H] Vulnerability fixed in Fortinet FortiMail
Fortinet released a patch for CVE-2026-104286, a critical vulnerability in FortiMail caused by path traversal and insufficient NULL-byte neutralization that allows unauthenticated attackers to write arbitrary files via crafted HTTP or HTTPS requests. The flaw affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1 with Identity Based Encryption (IBE) enabled, and is being actively exploited in the wild. Fortinet published indicators of compromise to help organizations investigate potential abuse and detect forensic evidence of compromise.
Why it matters: FortiMail administrators running affected versions with IBE enabled face immediate risk of arbitrary file writes by unauthenticated attackers; apply the security update immediately and use the published indicators of compromise to investigate for signs of exploitation.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
NCSC-2026-0398 [1.00] [M/H] Vulnerability fixed in Fortinet FortiMail
Fortinet released a patch for CVE-2026-104286, a critical vulnerability in FortiMail caused by path traversal and insufficient NULL-byte neutralization that allows unauthenticated attackers to write arbitrary files via crafted HTTP or HTTPS requests. The flaw affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1 with Identity Based Encryption (IBE) enabled, and is being actively exploited in the wild. Fortinet published indicators of compromise to help organizations investigate potential abuse and detect forensic evidence of compromise.
Why it matters: FortiMail administrators running affected versions with IBE enabled face immediate risk of arbitrary file writes by unauthenticated attackers; apply the security update immediately and use the published indicators of compromise to investigate for signs of exploitation.
- Source published
- First seen by Cybersecurity Tracker