Fortinet discloses actively exploited FortiMail zero-day CVE-2026-104286 (CVSS 9.8)
Tags Policy & Law · Product

Fortinet published an advisory on Oct 1, 2026 for CVE-2026-104286, a path-traversal (CWE-22) and NULL-byte (CWE-158) flaw in FortiMail that lets unauthenticated attackers write arbitrary files via crafted HTTP(S) requests, rated CVSS 9.8. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog the same day, giving US federal civilian agencies until Oct 4, 2026 to remediate. Affected versions span FortiMail 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8 and 7.2.0-7.2.9, and fixes (8.0.2/7.6.7/7.4.9) had not been released as of the advisory. Fortinet shared attack files, IP addresses and log entries as indicators of compromise, and recommended interim mitigations of disabling IBE or restricting management-interface access.
Technical significance
A CVSS 9.8 unauthenticated arbitrary-file-write in an internet-facing email gateway, exploited in the wild with no patch available, forces defenders into compensating controls rather than a clean upgrade. The three-day federal remediation deadline signals CISA treats the flaw as high-urgency, and the absence of a vendor fix means the exposure window may persist for organizations that cannot disable IBE or segment the management interface. Because FortiMail sits at the mail perimeter, a successful write primitive could be chained toward code execution or persistent access, though the advisory does not confirm post-exploitation behavior.