Fortinet FortiMail: Schwachstelle ermöglicht Manipulation von Dateien
NEOSEC enrichment — no mirror of the original source
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Fortinet FortiMail ausnutzen, um Dateien zu manipulieren.
Source: BSI CERT-Bund WID. For licensing reasons NEOSEC Intel does not mirror the full text verbatim. Full body and expert context live with the original.
Read the issue at BSI CERT-Bund WID →Full advisory
bsi:WID-SEC-2026-3701critical1 linked CVE
Open advisory with all CVEs →
More on FortiMail
Other advisories
- CVE-2026-104286criticalFortinet FortiMail: Schwachstelle ermöglicht Manipulation von Dateien
- CVE-2026-104286noneSicherheitsluecke -- CVE-2026-104286
- CVE-2026-104286noneEine Schwachstelle zur Pfad-Traversierung in Fortinet FortiMail 8.
- CVE-2025-53681mediumEine unzureichende Neutralisierung von Sonderzeichen in SQL-Befehlen (SQL-Injection) [CWE-89]-Schwachstelle in Fortinet FortiMail 7.
- CVE-2025-53681mediumEine unsachgemäße Neutralisierung spezieller Elemente in einem SQL-Befehl ("SQL-Injection"-Sicherheitsanfälligkeit [CWE-89]) in Fortinet FortiMail 7.
- CVE-2025-53681mediumAn improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 thr…
- CVE-2025-54972lowfortinet fortimail: Improper Neutralization of CRLF Sequences ('CRLF Injection')
- CVE-2025-54972nonefortinet fortimail: Improper Neutralization of CRLF Sequences ('CRLF Injection')
Other news entries
- Newsthehackernews2026-10-05⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
- Newstheregister-security2026-10-02Fortinet sounds the alarm over actively exploited FortiMail zero-day
- Vulnerabilitybsi-cert-bund-wid2026-10-02Fortinet FortiMail: Schwachstelle ermöglicht Manipulation von Dateien
- Newssecurityweek2026-10-02Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
- Newsncsc-nl2026-10-02NCSC-2026-0398 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiMail
- Newsthehackernews2026-10-02Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
- Newscert-fr2026-10-02Vulnérabilité dans Fortinet FortiMail (02 octobre 2026)
- Newsbleepingcomputer2026-10-01Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Source: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3701
ID