Fortinet Product Security Update Advisory (CVE-2026-104286)
Overview
A security update has been released to address a vulnerability in Fortinet products. The update applies to FortiMail and fixes the CVE-2026-104286 vulnerability.
Vulnerability Details
CVE-2026-104286 is a pre-authentication path traversal through which arbitrary file write vulnerabilities are exploited in FortiMail. Path traversal (an issue related to pathnames to restricted directories) is a type of vulnerability caused by improper handling of paths outside restricted directories.
Affected Products and Versions
- FortiMail 7.2.0 Through 7.2.9.
- FortiMail 7.4.0 Through 7.4.8.
- FortiMail 7.6.0 Through 7.6.6.
- FortiMail 8.0.0 Through 8.0.1.
Fixed Versions
- FortiMail 7.4.9 And later.
- FortiMail 7.6.7 And later.
- FortiMail 8.0.2 And later.
Recommendations
Fortinet recommends updating to the latest version with Vulnerability Patches, following the instructions on the reference site.