Fortinet Product Security Update Advisory (CVE-2026-104286)

Fortinet Product Security Update Advisory (CVE-2026-104286)

Overview

A security update has been released to address a vulnerability in Fortinet products. The update applies to FortiMail and fixes the CVE-2026-104286 vulnerability.

Vulnerability Details

CVE-2026-104286 is a pre-authentication path traversal through which arbitrary file write vulnerabilities are exploited in FortiMail. Path traversal (an issue related to pathnames to restricted directories) is a type of vulnerability caused by improper handling of paths outside restricted directories.

Affected Products and Versions

  • FortiMail 7.2.0 Through 7.2.9.
  • FortiMail 7.4.0 Through 7.4.8.
  • FortiMail 7.6.0 Through 7.6.6.
  • FortiMail 8.0.0 Through 8.0.1.

Fixed Versions

  • FortiMail 7.4.9 And later.
  • FortiMail 7.6.7 And later.
  • FortiMail 8.0.2 And later.

Recommendations

Fortinet recommends updating to the latest version with Vulnerability Patches, following the instructions on the reference site.