---
title: ช่องโหว่ความปลอดภัยของ FortiMail ถูกใช้โจมตี
url: https://www.dataloco.com/th/fortimail
published: 2026-10-05T05:24:10+00:00
language: th
section: ความปลอดภัย
source: https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html
organizations: CISA, Fortinet
publisher: Dataloco
---

# ช่องโหว่ความปลอดภัยของ FortiMail ถูกใช้โจมตี

หน่วยงานความมั่นคงปลอดภัยทางไซเบอร์และโครงสร้างพื้นฐานของสหรัฐอเมริกา (CISA) เมื่อวันพฤหัสบดีที่ผ่านมา ได้เพิ่มช่องโหว่ความปลอดภัยที่สำคัญซึ่งส่งผลกระทบต่อ Fortinet FortiMail ลงในแคตตาล็อกช่องโหว่ที่ถูกใช้ในการโจมตี (KEV) หลังจากมีรายงานการถูกใช้โจมตีอย่างต่อเนื่อง

ช่องโหว่นี้ถูกติดตามด้วยหมายเลข CVE-2026-104286 (คะแนน CVSS: 9.8) ซึ่งอนุญาตให้ผู้โจมตีที่ไม่ได้รับการตรวจสอบสามารถเขียนไฟล์ต่างๆ บนระบบฐานได้

Fortinet ระบุว่า "การจำกัดเส้นทางของไฟล์ไปยังไดเรกทอรีที่จำกัด ('path traversal') และการไม่สามารถจัดการ NULL byte หรือ NULL character อาจอนุญาตให้ผู้โจมตีที่ไม่ได้รับการตรวจสอบสามารถเขียนไฟล์ต่างๆ บนระบบฐานผ่านคำขอ HTTP หรือ HTTPS ที่ถูกสร้างขึ้น"

Fortinet ได้ยืนยันว่าช่องโหว่นี้ได้ถูกใช้ประโยชน์ในโลกจริงและได้แนะนำให้ลูกค้านำวิธีแก้ไขไปใช้จนกว่าจะมีการแก้ไขสำหรับบางเวอร์ชัน โดยแนะนำให้หน่วยงานของรัฐบาลกลางใช้แพตช์หรือวิธีการแก้ไขภายในวันที่ 4 ตุลาคม 2026

## This story in other languages

- [Português (Brasil)](https://www.dataloco.com/pt-br/falha-critica-do-fortimail-explorada-em-ataques-permite-gravacao-de-arquivos-nao-autenticada)
- [한국어](https://www.dataloco.com/ko/fortimail)
- [日本語](https://www.dataloco.com/ja/cisa)
- [中文](https://www.dataloco.com/zh/fortimail)
- [हिन्दी](https://www.dataloco.com/hi/mahatavaparanae-fortimail-shanaya-thana-sarakashha-thashha-ka-shashhanae-haaa)
- [Indonesia](https://www.dataloco.com/id/kelemahan-zero-day-kritis-fortimail-dieksploitasi-dalam-serangan)
- [Italiano](https://www.dataloco.com/it/flaw-critica-di-fortimail-sfruttata-in-attacchi-consente-scritture-di-file-arbitrari-non-autenticati)
- [Svenska](https://www.dataloco.com/sv/kritisk-sarbarhet-i-fortimail-utnyttjad-i-attacker)
- [Polski](https://www.dataloco.com/pl/krytyczna-luka-w-fortimail-wykorzystana-w-atakach-umozliwia-nieautoryzowane-zapisy-plikow)
- [עברית](https://www.dataloco.com/he/story-48)
- [Español](https://www.dataloco.com/es/falla-critica-de-fortimail-permite-escrituras-de-archivos-no-autenticadas)
- [Français](https://www.dataloco.com/fr/cisa-ajoute-une-faille-critique-de-fortimail-a-son-catalogue-de-vulnerabilites-exploitees)
