Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
Unpatched FortiMail zero-day CVE-2026-104286 is exploited in the wild and added to CISA KEV.
CISA and Fortinet warned that critical FortiMail zero-day CVE-2026-104286, scored CVSS 9.8, is being exploited in the wild and has no patch yet. The path-traversal and NULL-byte flaw lets attackers write arbitrary files through crafted HTTP or HTTPS requests and potentially execute code. Fortinet advises disabling IBE support or restricting the management interface, and CISA added the bug to the KEV catalog with a three-day federal deadline. Fixes are planned for FortiMail 7.4.9, 7.6.7, and 8.0.2, with no release date given.
- CVE-2026-104286 is a CVSS 9.8 FortiMail path-traversal zero-day.
- Crafted HTTP requests can write files and enable code execution.
- No patch yet; Fortinet urges disabling IBE or restricting management access.
- CISA added it to KEV with a three-day federal deadline.
- Affected builds span FortiMail 7.2, 7.4, 7.6, and 8.0.
Vulnerabilities mentionedAll →
- CVE-2026-1042869.82%Unauthenticated path traversal file write in Fortinet FortiMailpublished · Fortinet FortiMail KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-104286 |
Full article287 words · extracted from securityweek.com · click to collapse
The US Cybersecurity and Infrastructure Security Agency (CISA) and Fortinet on Thursday sounded the alarm on a critical FortiMail vulnerability that has been exploited in the wild. Patches have yet to be released.
Tracked as CVE-2026-104286 (CVSS score of 9.8), the zero-day is a path traversal and an improper neutralization of NULL byte or NULL character flaw that could allow attackers to write arbitrary files to the underlying system.
Threat actors could exploit the issue via crafted HTTP or HTTPS requests, potentially gaining arbitrary code or command execution.
Fortinet has published an advisory describing the security defect, urging organizations to disable the IBE feature support or disable access to the FortiMail management interface from the web and limit access to trusted sources.
“This has been reported to be exploited in the wild; customers are urged to apply the workaround,” the company said.
Fortinet also published indicators of compromise (IoCs) to help security teams hunt for potential intrusions.
Advertisement. Scroll to continue reading.
On Thursday, CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to address it within three days, as mandated by BOD 26-04.
According to Fortinet, the security bug was discovered internally and affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1.
The company says fixes will be included in the upcoming FortiMail versions 7.4.9, 7.6.7, and 8.0.2, but has not provided a release timeline.
Neither Fortinet nor CISA has provided details on the observed attacks.
Related: Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
Related: Zammad Zero-Days Exploited in AI-Powered DIVD Hack
Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
Related: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Text extracted automatically; images, tables and formatting may be missing. Original: