Vulnerabilities
Vulnerable Software
Security Vulnerabilities
CVE-2026-104286
Known exploited
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
CVSS Score
9.8
EPSS Score
0.022
Published
2026-10-01
Out-of-bounds Write vulnerability in Apache HTTP Server's mod_charset_lite. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-10-01
Missing authentication checks in mod_auth_digest in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an unauthenticated remote client to cause a denial of service (forced re-authentication) via forged Authorization headers when Digest authentication is enabled with AuthDigestNcCheck . Users are recommended to upgrade to version 2.4.69, which fixes this issue.
CVSS Score
7.5
EPSS Score
0.006
Published
2026-10-01
NULL Pointer Dereference vulnerability in Apache HTTP Servers mod_heartmonitor over unicast listener. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-10-01
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HTTP Server's mod_session_cookie module.   When SessionCookieRemove changes across internal redirects, the session cookie may still be passed to a backend server. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.
CVSS Score
7.5
EPSS Score
0.004
Published
2026-10-01
Deployment of wrong handler vulnerability in Apache HTTP Server allows the target of some internal redirects from CGI programs to also be treated as CGI and executed. The target must already be in a directory enabled for CGI and have no other extension understood by mod_mime. This issue affects Apache HTTP Server: from 2.4.60 through 2.4.68.
CVSS Score
3.7
EPSS Score
0.005
Published
2026-10-01
A memory calculation bug in mod_dav in Apache httpd 2.4.67 and earlier allows an attacker with permission to create WebDAV locks to crash server child processes. Users are recommended to upgrade to version 2.4.69, which fixes this issue
CVSS Score
4.3
EPSS Score
0.004
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs
CVSS Score
4.3
EPSS Score
0.002
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications
CVSS Score
5.4
EPSS Score
0.001
Published
2026-10-01
In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration
CVSS Score
5.5
EPSS Score
0.002
Published
2026-10-01


Contact Us

Shodan ® - All rights reserved