PSIRT
Reported 02 Oct 2026 by otx · Severity: medium
A critical path traversal vulnerability combined with improper NULL byte neutralization in FortiMail versions 7.2 through 8.0 allows unauthenticated attackers to write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. This vulnerability is actively