Fortinet warns of critical FortiMail zero-day (CVE-2026-104286) under active exploitation
Tags Policy & Law

Fortinet disclosed a critical path-traversal and null-byte vulnerability in FortiMail, tracked as CVE-2026-104286 with a CVSS score of 9.8, that is being actively exploited in zero-day attacks to run unauthorized code. The flaw affects the FortiMail management interface across versions 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8 and 7.2.0-7.2.9, and allows an unauthenticated attacker to write arbitrary files via crafted HTTP or HTTPS requests. Patches are not yet available for the 7.4, 7.6 and 8.0 branches; Fortinet recommends disabling IBE support or restricting management-interface access. CISA added the CVE to its Known Exploited Vulnerabilities catalog and requires federal agencies to perform forensic triage and mitigate by October 4.
Technical significance
An unauthenticated file-write primitive on an internet-facing mail gateway is a high-value foothold, and the absence of patches for three supported branches forces defenders onto workarounds. The CISA KEV listing and October 4 federal deadline signal that exploitation is confirmed and widespread enough to warrant emergency triage.