FortiMail's path check and its file write disagree about where a filename ends, and attackers are already there
Fortinet's advisory of 1 October describes two weaknesses in one request: a path traversal and improper handling of the null byte. Together they let an unauthenticated attacker write files anywhere on a mail gateway that exists to face the internet. It is exploited, it scores 9.8, and the 7.2 branch has no fix at all.