{"schema":"hottub-news/story/v1","story":"st_c436amf7e2bvhhpz6gdq","title":"CISA警示FortiMail漏洞CVE-2026-104286已遭實際利用","title_en":"CISA warns that FortiMail vulnerability CVE-2026-104286 has been exploited","outlets":1,"brief":null,"page":"https://hottub.news/stories/cisa-warns-that-fortimail-vulnerability-cve-2026-104286-has-been-c436amf7e2","count":1,"items":[{"id":"n_c436amf7e2bvhhpz6gdq","seq":1475689,"kind":"article","title":"CISA警示FortiMail漏洞CVE-2026-104286已遭實際利用","title_en":"CISA warns that FortiMail vulnerability CVE-2026-104286 has been exploited","url":"https://www.ithome.com.tw/news/179386","summary":"新聞 美國網路與基礎設施安全局（CISA）維護的已知遭利用漏洞清單（KEV）， 10月1日新增CVE-2026-104286 ，這是存在Fortinet郵件安全閘道設備FortiMail的路徑遍歷漏洞，聯邦政府各民事執行單位須在10月4日前完成修補。 根據CISA公告當中的說明，CVE-2026-104286問題出在FortiMail存在路徑遍歷漏洞，以及對NULL位元組或NULL字元處理不當的漏洞，未經身分驗證的攻擊者可發出特製的 HTTP 或 HTTPS 請求，趁機在底層系統上寫入任意檔案。 CVE-2026-104286也收錄在 美國國家弱點資料庫（NVD） 與 MITRE維護的CVE網站 ，關於漏洞的成因描述是特定路徑名稱對受限目錄的限制不當（亦即路徑遍歷），其CVSS嚴重程度被評為9.8分，當中列出的受影響版本包括FortiMail的8.0.0至8.0.1版、7.6.0至7.6.6版、7.4.0至7.4.8版、7.2.0至7.2.9版。 10月1日Fortinet也發布 此漏洞的公告FG-IR-26-175…","published":"2026-10-03T03:59:17Z","seen":"2026-10-03T04:41:09Z","lang":"zh","country":"TW","source":{"id":"kite-ithome-com-tw-c23d09","name":"ithome.com.tw","domain":"ithome.com.tw","outlet":{"wikidata":"Q123398745","name":"iThome","type":"magazine","country":"TW","designations":["magazine","news website"]}},"via":"kite-ithome-com-tw-c23d09","authors":["李宗翰"],"entities":[{"id":"Q5205058","name":"Cybersecurity and Infrastructure Security Agency","type":"org"}],"story":"st_c436amf7e2bvhhpz6gdq","category":"science-technology","category_p":0.44999998807907104,"category2":"crime-law","sentiment":"negative","tone":-0.5799999833106995,"political":0.2199999988079071}]}