← nejvýznamnější zprávy · všechny zprávy

poslední zpráva

SPOJENO AI KEV ✓

NCSC-2026-0398 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiMail

Fortinet heeft een kwetsbaarheid verholpen in FortiMail. FortiMail bevat een kritieke kwetsbaarheid (CVE-2026-104286) in de verwerking van bestandspaden, veroorzaakt door een combinatie van Path Traversal (CWE-22) en onvoldoende neutralisatie van NULL-bytes (CWE-158). Een niet-geauthenticeerde aanvaller kan via speciaal vervaardigde HTTP- of HTTPS-verzoeken willekeurige bestanden op het onderliggende systeem schrijven. De kwetsbaarheid wordt actief geëxploiteerd. Getroffen zijn FortiMail 7.2…

Číst originál na NCSC-NL →

5 zpráv z 5 zdrojů · první · zachyceno CZ · EN/orig

Fortinet NL IT US

tg: zneužíváno tg: zranitelnost

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-104286 9.8 3.1 · fortinet KEV ✓ –

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.8.

Jak se o tom psalo 5

  1. · NCSC-NL NL nadpis události

    NCSC-2026-0398 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiMail

    Fortinet heeft een kwetsbaarheid verholpen in FortiMail. FortiMail bevat een kritieke kwetsbaarheid (CVE-2026-104286) in de verwerking van bestandspaden, veroorzaakt door een combinatie van Path Traversal (CWE-22) en onvoldoende neutralisatie van NULL-bytes (CWE-158). Een niet-geauthenticeerde aanvaller kan via speciaal vervaardigde HTTP- of HTTPS-verzoeken willekeurige bestanden op het onderliggende systeem schrijven. De kwetsbaarheid wordt actief geëxploiteerd. Getroffen zijn FortiMail 7.2…

  2. · CSIRT Itálie (ACN) IT

    Fortinet: rilevato sfruttamento in rete della CVE-2026-104286 relativa a FortiMail

    Rilevato lo sfruttamento in rete di una vulnerabilità critica, identificata tramite la CVE-2026-104286, in FortiMail, soluzione Fortinet per la sicurezza della posta elettronica.

  3. · BleepingComputer US

    Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

    Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]

  4. · zachyceno · Fortinet PSIRT US

    Improper limitation of a pathname to a restricted directory

    CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.This has been reported to be exploited in the wild, customers are urged to apply the workaround below. Revised on 2026-10-01 00:00:00

  5. · zachyceno · CISA KEV US

    Fortinet FortiMail Path Traversal Vulnerability (CVE-2026-104286)

    CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities catalog. Affected product: Fortinet FortiMail. Remediation due date: 2026-10-04.