poslední zpráva
SPOJENO AI KEV ✓
NCSC-2026-0398 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiMail
Fortinet heeft een kwetsbaarheid verholpen in FortiMail. FortiMail bevat een kritieke kwetsbaarheid (CVE-2026-104286) in de verwerking van bestandspaden, veroorzaakt door een combinatie van Path Traversal (CWE-22) en onvoldoende neutralisatie van NULL-bytes (CWE-158). Een niet-geauthenticeerde aanvaller kan via speciaal vervaardigde HTTP- of HTTPS-verzoeken willekeurige bestanden op het onderliggende systeem schrijven. De kwetsbaarheid wordt actief geëxploiteerd. Getroffen zijn FortiMail 7.2…
Fortinet NL IT US
CVE v události 1
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-104286 | 9.8 3.1 · fortinet | KEV ✓ | – |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.
Jak se o tom psalo 5
-
· NCSC-NL NL nadpis události
NCSC-2026-0398 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiMail
Fortinet heeft een kwetsbaarheid verholpen in FortiMail. FortiMail bevat een kritieke kwetsbaarheid (CVE-2026-104286) in de verwerking van bestandspaden, veroorzaakt door een combinatie van Path Traversal (CWE-22) en onvoldoende neutralisatie van NULL-bytes (CWE-158). Een niet-geauthenticeerde aanvaller kan via speciaal vervaardigde HTTP- of HTTPS-verzoeken willekeurige bestanden op het onderliggende systeem schrijven. De kwetsbaarheid wordt actief geëxploiteerd. Getroffen zijn FortiMail 7.2…
-
· CSIRT Itálie (ACN) IT
Fortinet: rilevato sfruttamento in rete della CVE-2026-104286 relativa a FortiMail
Rilevato lo sfruttamento in rete di una vulnerabilità critica, identificata tramite la CVE-2026-104286, in FortiMail, soluzione Fortinet per la sicurezza della posta elettronica.
-
· BleepingComputer US
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]
-
· zachyceno · Fortinet PSIRT US
Improper limitation of a pathname to a restricted directory
CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.This has been reported to be exploited in the wild, customers are urged to apply the workaround below. Revised on 2026-10-01 00:00:00
-
· zachyceno · CISA KEV US
Fortinet FortiMail Path Traversal Vulnerability (CVE-2026-104286)
CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities catalog. Affected product: Fortinet FortiMail. Remediation due date: 2026-10-04.