Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
CISA added exploited FortiMail flaw CVE-2026-104286, a critical unauthenticated file-write bug, to the KEV catalog.
CISA added Fortinet FortiMail CVE-2026-104286, a CVSS 9.8 path-traversal and NULL-byte flaw, to the Known Exploited Vulnerabilities catalog after confirmed active exploitation. An unauthenticated attacker can write arbitrary files via crafted HTTP or HTTPS requests. Affected branches are FortiMail 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9, with some fixes still upcoming. Until patches ship, Fortinet advises disabling IBE and restricting management access; federal agencies must mitigate by October 4, 2026.