Fortinet FortiMail has a path traversal flaw combined with improper neutralization of a NULL byte (CWE-22 and CWE-158). An unauthenticated attacker can send crafted HTTP or HTTPS requests that write arbitrary files on the underlying system. Successful exploitation can place attacker-controlled content on the appliance and may be used to alter its behavior or persist access. The issue affects Fortinet FortiMail; specific version ranges are not listed in the available data, and CVSS has not yet been scored. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-10-01, so exploitation in the wild is confirmed, while ransomware use and a public proof of concept are not known.
What to do: Apply Fortinet's fixes or mitigations for CVE-2026-104286 immediately, in line with CISA BOD 26-04, and treat internet-exposed FortiMail as highest priority. If a vendor fix is unavailable, restrict HTTP/HTTPS management access or discontinue use. Review systems added to the KEV catalog on 2026-10-01 for unexpected file writes and follow CISA forensics triage requirements.
Affected
Fortinet FortiMail
—
Estimated exposure
moderateOn the order of 1,000–10,000 internet-exposed FortiMail systems (estimate; version-specific exposure unknown) — No install or scan count is in the CVE data; the estimate reflects FortiMail's typical enterprise email-gateway deployment and publicly observed internet-exposed management interfaces, which are usually in the thousands rather than a mass…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
CISA Known Exploited Vulnerability
Affected
Fortinet FortiMail
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Fortinet says attackers are exploiting critical FortiMail zero-day CVE-2026-104286 to write files without authentication.
Fortinet warned that CVE-2026-104286, a critical FortiMail flaw scored CVSS 9.8, is being exploited in the wild. Unauthenticated attackers can send crafted HTTP or HTTPS requests that combine path traversal and improper null-character handling to write arbitrary files and potentially execute commands. Versions 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9 are affected, and fixes for several branches remain upcoming. CISA placed the flaw in its Known Exploited Vulnerabilities catalog, requiring US federal civilian agencies to triage and mitigate by October 4, while Fortinet urges disabling unused Identity Based Encryption and blocking internet access to the management interface.
Unpatched FortiMail zero-day CVE-2026-104286 is exploited in the wild and added to CISA KEV.
CISA and Fortinet warned that critical FortiMail zero-day CVE-2026-104286, scored CVSS 9.8, is being exploited in the wild and has no patch yet. The path-traversal and NULL-byte flaw lets attackers write arbitrary files through crafted HTTP or HTTPS requests and potentially execute code. Fortinet advises disabling IBE support or restricting the management interface, and CISA added the bug to the KEV catalog with a three-day federal deadline. Fixes are planned for FortiMail 7.4.9, 7.6.7, and 8.0.2, with no release date given.
Attackers are exploiting critical FortiMail zero-day CVE-2026-104286 to write files without authentication.
Fortinet advisory FG-IR-26-175 says attackers are exploiting CVE-2026-104286, a critical FortiMail zero-day scored CVSS 9.8. Unauthenticated attackers can write files through crafted HTTP or HTTPS requests by combining path traversal (CWE-22) with improper NULL-byte handling (CWE-158). Affected releases span FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9, while fixes such as 8.0.2, 7.6.7, and 7.4.9 were still upcoming. Fortinet urges disabling IBE or restricting management access and lists added files, hashes, and IPs 79.141.169.187 and 45.129.0.192. This is separate from earlier CVE-2025-32756.
Attackers are exploiting critical FortiMail zero-day CVE-2026-104286 before patches are available.
Fortinet warned that CVE-2026-104286, a critical FortiMail zero-day scored 9.8, is being exploited in the wild. An unauthenticated attacker can combine path traversal and null-byte handling flaws to write arbitrary files through crafted HTTP or HTTPS requests. Affected versions are 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9; fixes in 8.0.2, 7.6.7, and 7.4.9 were not yet available. CISA added the flaw to its KEV catalog the same day and set a US federal deadline of October 4, 2026. Fortinet advised disabling identity-based encryption or restricting the management interface and published attack indicators.
CISA added exploited FortiMail flaw CVE-2026-104286, a critical unauthenticated file-write bug, to the KEV catalog.
CISA added Fortinet FortiMail CVE-2026-104286, a CVSS 9.8 path-traversal and NULL-byte flaw, to the Known Exploited Vulnerabilities catalog after confirmed active exploitation. An unauthenticated attacker can write arbitrary files via crafted HTTP or HTTPS requests. Affected branches are FortiMail 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9, with some fixes still upcoming. Until patches ship, Fortinet advises disabling IBE and restricting management access; federal agencies must mitigate by October 4, 2026.
Attackers are exploiting critical FortiMail path-traversal CVE-2026-104286 to write files and compromise email appliances.
Fortinet advisory FG-IR-26-175 discloses CVE-2026-104286, a CVSS 9.8 path-traversal flaw in FortiMail that lets unauthenticated attackers write arbitrary files through crafted HTTP or HTTPS requests. Fortinet says the bug is being exploited and that file writes could lead to code or command execution. Affected versions include 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9; fixes 8.0.2, 7.6.7, and 7.4.9 are identified, while 7.2 users are told to move to 7.4 or later. Until patches, Fortinet advises disabling Identity-Based Encryption or limiting management exposure, and published IOCs including suspicious files and IPs 79.141.169.187 and 45.129.0.192.
Fortinet says critical FortiMail flaw CVE-2026-104286 is being exploited in zero-day attacks.
Fortinet warned that CVE-2026-104286, a critical FortiMail flaw scored CVSS 9.8, is under active zero-day exploitation. An unauthenticated path-traversal and null-byte bug lets attackers write arbitrary files via crafted HTTP or HTTPS requests to the management interface. It affects FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1, and patches for 7.4, 7.6, and 8.0 are still pending. CISA added the flaw to the KEV catalog with a federal mitigation deadline of October 4, 2026, and Fortinet published file hashes plus IPs 79.141.169.187 and 45.129.0.192.
CISA added actively exploited Fortinet FortiMail path traversal CVE-2026-104286 (CVSS 9.8) to the KEV catalog.
The U.S. CISA added Fortinet FortiMail CVE-2026-104286, a CVSS 9.8 path traversal and NULL-byte handling flaw, to its Known Exploited Vulnerabilities catalog. An unauthenticated attacker can use crafted HTTP or HTTPS requests to bypass path checks and write arbitrary files on the system. Fortinet says the issue is exploited in the wild and affects FortiMail 7.2 through 8.0; fixed versions are still upcoming, and a workaround is to disable Identity-Based Encryption or restrict management-interface access. Federal civilian agencies must remediate by October 3, 2026 under BOD 22-01.
Canada's Cyber Centre warns FortiMail path-traversal CVE-2026-104286 is exploited in the wild and listed in CISA KEV.
On October 1, 2026, the Canadian Centre for Cyber Security issued advisory AV26-989 on FortiMail vulnerabilities. Affected versions are FortiMail 8.0 before 8.0.2, 7.6 before 7.6.7, and 7.4 before 7.4.9; 7.2 users are directed to upgrade to 7.4 or later. Fortinet says CVE-2026-104286, an improper pathname limitation, is exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog the same day.
CISA added actively exploited Fortinet FortiMail path traversal CVE-2026-104286 to the KEV catalog.
CISA added CVE-2026-104286, a Fortinet FortiMail path traversal vulnerability, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. The alert points to Binding Operational Directive 26-04, which requires federal civilian agencies to prioritize KEV flaws on exposed assets and to check for compromise before patching. CISA encourages every organization to remediate cataloged vulnerabilities using a risk-based process.