FortiMail zero-day CVE-2026-104286 exploited in the wild; Canada's Cyber Centre adds advisory as patches remain pending
Unauthenticated attackers are exploiting unpatched FortiMail zero-day CVE-2026-104286 (CVSS 9.8) to write arbitrary files; fixes are still unavailable, CISA added it to the KEV catalog on October 1, 2026, and sources disagree on the federal remediation…
Fortinet advisory FG-IR-26-175 says CVE-2026-104286, a critical FortiMail flaw scored CVSS 9.8, is under active zero-day exploitation; no threat actor has been named, and Cyber Security News said the issue is separate from earlier CVE-2025-32756. Unauthenticated attackers can write arbitrary files through crafted HTTP or HTTPS requests to the management interface by combining path traversal (CWE-22) with improper NULL-byte handling (CWE-158); GBHackers, SecurityWeek, and The Register report those writes could lead to code or command execution. Affected versions are FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1; identified fixes 7.4.9, 7.6.7, and 8.0.2 were still upcoming or not yet available, SecurityWeek said no release date was given, and both GBHackers and the Canadian Centre for Cyber Security direct 7.2 users to move to 7.4 or later. Until patches, Fortinet advises disabling Identity-Based Encryption—The Register specifies unused IBE—or restricting management access, including keeping the interface off the internet, and published indicators including ld.so.preload, webconsole, file hashes, and IPs 79.141.169.187 and 45.129.0.192. CISA added the flaw to the KEV catalog, with the Canadian Cyber Centre dating that addition October 1, 2026, but sources disagree on the federal deadline: BleepingComputer, Help Net Security, and The Register reported October 4, 2026, Security Affairs reported October 3, 2026 under BOD 22-01, and SecurityWeek described a three-day deadline without a calendar date.
- CVE-2026-104286 is a CVSS 9.8 unauthenticated flaw in FortiMail disclosed in Fortinet advisory FG-IR-26-175 and confirmed exploited in the wild; no threat actor has been named.
- The bug combines path traversal (CWE-22) with improper NULL-byte handling (CWE-158), allowing arbitrary file writes via crafted HTTP or HTTPS requests to the management interface, with potential code or command execution reported by…
- Affected versions: FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1.
- Fixes 7.4.9, 7.6.7, and 8.0.2 were still upcoming with no release date given; FortiMail 7.2 has no fix listed and users are directed to upgrade to 7.4 or later.
- Workarounds until patch availability: disable Identity-Based Encryption (The Register specifies unused IBE) or restrict management-interface access, including keeping it off the internet.
Coverage timelineoldest first · each row is one article
- · 1d agoFortinet warns of critical FortiMail flaw exploited in zero-day attacks
BleepingComputer· 85
Fortinet says critical FortiMail flaw CVE-2026-104286 is being exploited in zero-day attacks.
- · 21h agoCritical Fortinet FortiMail 0-Day Vulnerability Actively Exploited in Attacks
Cyber Security News· 88
Attackers are exploiting critical FortiMail zero-day CVE-2026-104286 to write files without authentication.
- · 19h ago
Vulnerabilities in this storyAll →
- CVE-2025-327569.830%Stack-based overflow RCE in Fortinet FortiMail, FortiVoice, FortiNDR, FortiFonepublished · Fortinet FortiMail KEV