Critical FortiMail Path Traversal Zero‑Day Alert
🔒 The U.S. CISA has added a critical Fortinet FortiMail flaw (CVE-2026-104286, CVSS 9.8) to its KEV catalog after reports of active exploitation. The vulnerability allows unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests due to path traversal and NULL byte handling issues. Fortinet has identified affected FortiMail versions and provided upgrade guidance and temporary workarounds, including disabling IBE and restricting management access.
