Fortinet sounds the alarm over actively exploited FortiMail zero-day
Fortinet says attackers are exploiting critical FortiMail zero-day CVE-2026-104286 to write files without authentication.
Fortinet warned that CVE-2026-104286, a critical FortiMail flaw scored CVSS 9.8, is being exploited in the wild. Unauthenticated attackers can send crafted HTTP or HTTPS requests that combine path traversal and improper null-character handling to write arbitrary files and potentially execute commands. Versions 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9 are affected, and fixes for several branches remain upcoming. CISA placed the flaw in its Known Exploited Vulnerabilities catalog, requiring US federal civilian agencies to triage and mitigate by October 4, while Fortinet urges disabling unused Identity Based Encryption and blocking internet access to the management interface.
- CVE-2026-104286 is a CVSS 9.8 unauthenticated file-write flaw in FortiMail.
- Fortinet and CISA say exploitation is underway and listed the bug in KEV.
- Affected branches span 7.2 through 8.0; several fixes remain upcoming.
- Disable unused Identity Based Encryption and keep management interfaces off the internet.
- US federal civilian agencies must triage and mitigate by October 4.
Vulnerabilities mentionedAll →
- CVE-2026-1042869.82%Unauthenticated path traversal file write in Fortinet FortiMailpublished · Fortinet FortiMail KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-104286 |
Full article358 words · extracted from theregister.com · click to collapse
security
No login required, exploitation underway, and some admins are still waiting for patches
Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in.
The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform.
Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system.
REG AD
Writing files to certain locations could allow an attacker to execute code or commands on the appliance.
REG AD
Fortinet says the flaw affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.
The vendor's advisory says CVE-2026-104286 "is being exploited in the wild," although it doesn't say when the attacks began, who is behind them, or how many customers may have been compromised.
It has, however, published indicators administrators can hunt for on their systems. These include suspicious files and configuration changes, along with IP addresses associated with the attacks.
CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, directing US federal civilian agencies to carry out forensic triage and apply mitigations by October 4.
Fortinet lists fixes for several affected branches as "upcoming," leaving customers on those versions reliant on workarounds until updates arrive.
In the meantime, Fortinet recommends disabling Identity Based Encryption if it isn't required. Where that's not possible, customers should prevent the FortiMail management interface from being reachable from the internet and restrict access to trusted private networks.
Administrators should also check for signs of compromise: applying a workaround will not remove any files or persistence mechanisms attackers may already have planted.
It's not Fortinet's first encounter with attackers making themselves at home on its network appliances this year. In June, credentials linked to around 75,000 FortiGate firewalls turned up in criminal hands, though Fortinet said the data came from previous incidents and brute-force attacks rather than a fresh breach. ®