CVE-2025-53681EPSS p27.4%
CVE-2025-53681CVE-2025-53681
fortinet / fortimail
Description
An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.
Scoring
| CVSS | 7.2 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.36% probability of exploitation · percentile 27.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |