U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
CISA added actively exploited Fortinet FortiMail path traversal CVE-2026-104286 (CVSS 9.8) to the KEV catalog.
The U.S. CISA added Fortinet FortiMail CVE-2026-104286, a CVSS 9.8 path traversal and NULL-byte handling flaw, to its Known Exploited Vulnerabilities catalog. An unauthenticated attacker can use crafted HTTP or HTTPS requests to bypass path checks and write arbitrary files on the system. Fortinet says the issue is exploited in the wild and affects FortiMail 7.2 through 8.0; fixed versions are still upcoming, and a workaround is to disable Identity-Based Encryption or restrict management-interface access. Federal civilian agencies must remediate by October 3, 2026 under BOD 22-01.
- CVE-2026-104286 is a CVSS 9.8 unauthenticated path traversal in FortiMail.
- Crafted HTTP or HTTPS requests can write arbitrary files on the system.
- Fortinet says the flaw is exploited in the wild; no actor details released.
- FortiMail 7.2 through 8.0 are affected; fixed releases are still upcoming.
- Federal agencies must remediate by October 3, 2026 under BOD 22-01.
Vulnerabilities mentionedAll →
- CVE-2026-1042869.82%Unauthenticated path traversal file write in Fortinet FortiMailpublished · Fortinet FortiMail KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-104286 |
Full article378 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog.
The flaw is a path traversal vulnerability that can be triggered through specially crafted HTTP or HTTPS requests. An unauthenticated attacker can exploit the issue to bypass restrictions on file paths and write arbitrary files to the underlying system.
The vulnerability also involves improper handling of NULL characters, which can help the attacker bypass security checks. The flaw is reportedly being exploited in the wild, so affected customers are urged to apply the recommended workaround.
“An Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.” reads the advisory. “This has been reported to be exploited in the wild”
The company did not disclose how many customers were affected, when the attacks started, who was behind them, or technical details of the attacks.
Below are the affected versions and the released updates:
| Version | Affected | Solution |
|---|---|---|
| FortiMail 8.0 | 8.0.0 through 8.0.1 | Upgrade to upcoming 8.0.2 or above |
| FortiMail 7.6 | 7.6.0 through 7.6.6 | Upgrade to upcoming 7.6.7 or above |
| FortiMail 7.4 | 7.4.0 through 7.4.8 | Upgrade to upcoming 7.4.9 or above |
| FortiMail 7.2 | 7.2.0 through 7.2.9 | Upgrade to branch 7.4 or above |
As a temporary workaround, customers should disable the IBE (Identity-Based Encryption) feature using the recommended CLI command. Alternatively, access to the FortiMail management interface should be blocked from the internet or limited to trusted private networks.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaw by October 3rd, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)