Fortinet
Fortinet Fortimail: vulnerabilidades y CVE
Fortinet Fortimail tiene 47 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 8 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE47
Últimos 12 meses5
Críticas8
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-104286 | Crítica (9.8) | 1.8% | ⚠ Explotación activa | 1 oct 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0… |
| CVE-2025-32756 | Crítica (9.8) | 30% | ⚠ Explotación activa | 13 may 2025 | A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-104286 | Crítica (9.8) | 1.8% | ⚠ Explotación activa | 1 oct 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0… |
| CVE-2025-53681 | Alta (7.2) | 0.36% | — | 12 may 2026 | An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0… |
| CVE-2025-55717 | Media (4) | 0.08% | — | 10 mar 2026 | A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8,… |
| CVE-2025-54972 | Media (4.3) | 0.20% | — | 18 nov 2025 | An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an… |
| CVE-2024-47569 | Media (4.3) | 0.47% | — | 14 oct 2025 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager… |
| CVE-2024-40588 | Media (4.4) | 0.18% | — | 12 ago 2025 | Multiple relative path traversal vulnerabilities [CWE-23] vulnerability in Fortinet FortiCamera 2.1 all versions, FortiCamera 2.0.0, FortiCamera 1.1 all versions, FortiCamera 1.0 all versions, FortiMail 7.6.0 through… |
| CVE-2025-32756 | Crítica (9.8) | 30% | ⚠ Explotación activa | 13 may 2025 | A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0… |
| CVE-2023-33302 | Alta (8.8) | 0.37% | — | 31 mar 2025 | A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 and FortiNDR administrative interface… |
| CVE-2021-24008 | Media (5.3) | 0.50% | — | 28 mar 2025 | An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and below, version 5.2.0, version 5.1.0, version 5.0.0, version 4.7.0,… |
| CVE-2021-26091 | Alta (7.5) | 0.31% | — | 24 mar 2025 | A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an… |
| CVE-2023-47539 | Crítica (9.8) | 1.0% | — | 18 mar 2025 | An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP… |
| CVE-2024-46663 | Media (6.7) | 0.18% | — | 11 mar 2025 | A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI… |
| CVE-2022-23439 | Media (6.1) | 0.45% | — | 22 ene 2025 | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver |
| CVE-2024-56497 | Media (6.7) | 0.59% | — | 14 ene 2025 | An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions… |
| CVE-2022-27488 | Alta (8.8) | 0.49% | — | 13 dic 2023 | A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through… |
| CVE-2023-45582 | Alta (7.3) | 0.52% | — | 14 nov 2023 | An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to… |
| CVE-2023-36633 | Media (5.4) | 0.47% | — | 14 nov 2023 | An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via… |
| CVE-2023-36637 | Media (5.4) | 0.39% | — | 10 oct 2023 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's… |
| CVE-2023-36556 | Alta (8.8) | 0.84% | — | 10 oct 2023 | An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the… |
| CVE-2022-29056 | Media (5.3) | 1.8% | — | 9 mar 2023 | A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially… |
| CVE-2022-39945 | Media (6.5) | 0.38% | — | 2 nov 2022 | An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to… |
| CVE-2022-26122 | Alta (8.6) | 0.48% | — | 2 nov 2022 | An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV… |
| CVE-2022-26114 | Media (6.1) | 0.47% | — | 6 sept 2022 | An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via… |
| CVE-2022-22299 | Alta (7.8) | 0.21% | — | 5 ago 2022 | A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0… |
| CVE-2021-32586 | Crítica (9.8) | 1.1% | — | 1 mar 2022 | An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically… |
| CVE-2021-36166 | Crítica (9.8) | 1.5% | — | 1 mar 2022 | An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's… |
| CVE-2021-43062 | Media (6.1) | 13% | — | 2 feb 2022 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below, version 6.3.7 and below, version 6.0.11 and below allows… |
| CVE-2020-15933 | Media (5.3) | 0.77% | — | 5 ene 2022 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below FortiMail versions 6.4.1 and 6.4.0 allows attacker to obtain potentially… |
| CVE-2021-32591 | Media (5.3) | 0.93% | — | 8 dic 2021 | A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may… |
| CVE-2021-42757 | Media (6.7) | 0.52% | — | 8 dic 2021 | A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.