CVE-2026-104286
Fortinet FortiMail
Parchea ya: se está explotando
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
En las noticias
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks · BleepingComputer