CVE-2021-32586

CRITICAL

An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpr...

Affects 1 product across 1 vendor.

BCS7.14
CVSS 3.19.8
EPSS1.1%
Percentile63th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-20: Improper Input Validation

Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.

Related Attack Patterns (CAPEC)
CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters
via CWE-20
CAPEC-7 Blind SQL Injection
via CWE-20
CAPEC-8 Buffer Overflow in an API Call
via CWE-20
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-20
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-20
Show all 51
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical vulnerability in FortiMail's web server CGI facilities allows unauthenticated attackers to alter the environment of the underlying script interpreter through crafted HTTP requests.

BSID: BS-2022-GLOBAL-275551-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2021-32586?
A critical vulnerability in FortiMail's web server CGI facilities allows unauthenticated attackers to alter the environment of the underlying script interpreter through crafted HTTP requests.
What is the CVSS score for CVE-2021-32586?
CVE-2021-32586 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.1%.
Is CVE-2021-32586 actively exploited?
No confirmed active exploitation of CVE-2021-32586 as of 2026-05-30.
How do I remediate CVE-2021-32586?
Priority: IMMEDIATE. Advisory: https://fortiguard.com/psirt/FG-IR-21-008 PSIRT: [email protected]
What systems are affected by CVE-2021-32586?
CVE-2021-32586 affects: Fortinet.
Vulnerability Details
CVE IDCVE-2021-32586
BSIDBS-2022-GLOBAL-275551-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2022-03-01
Last Modified2024-11-21
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability stems from improper input validation in the CGI facilities of FortiMail versions prior to 7.0.1. An attacker can exploit this by sending specially crafted HTTP requests to manipulate the script interpreter's environment, potentially leading to remote code execution.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Fortinet Fortimail —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 1671 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashb16fff7e791db057e7c3788d96ea483efd3a731b43896952c7157a1766252adf0a5a66ff32b02e6b62c34ed4a65ea84f43840069e47793efaf806f6bd62bb25a
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2017-7336 9.8 A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower ver... CVE-2018-13379 9.8 An Improper Limitation of a Pathname to a Restricted Directory ("Path Travers... CVE-2016-4573 9.8 Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-... CVE-2015-3616 9.8 SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2...
View all Fortinet CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →