Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
Fortinet FortiMail zero-day vulnerability (CVE-2026-104286) exploited in the wild.
Summary
CISA and Fortinet have issued warnings about a critical zero-day vulnerability, CVE-2026-104286, affecting multiple versions of FortiMail. This path traversal flaw allows attackers to write arbitrary files and potentially execute code. The vulnerability has reportedly been exploited in the wild, and CISA has added it to its Known Exploited Vulnerabilities catalog, mandating federal agencies to address it within three days. While patches are not yet available, Fortinet recommends disabling the IBE feature or restricting web management access as workarounds.
Full text
The US Cybersecurity and Infrastructure Security Agency (CISA) and Fortinet on Thursday sounded the alarm on a critical FortiMail vulnerability that has been exploited in the wild. Patches have yet to be released. Tracked as CVE-2026-104286 (CVSS score of 9.8), the zero-day is a path traversal and an improper neutralization of NULL byte or NULL character flaw that could allow attackers to write arbitrary files to the underlying system. Threat actors could exploit the issue via crafted HTTP or HTTPS requests, potentially gaining arbitrary code or command execution. Fortinet has published an advisory describing the security defect, urging organizations to disable the IBE feature support or disable access to the FortiMail management interface from the web and limit access to trusted sources. “This has been reported to be exploited in the wild; customers are urged to apply the workaround,” the company said. Fortinet also published indicators of compromise (IoCs) to help security teams hunt for potential intrusions.Advertisement. Scroll to continue reading. On Thursday, CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to address it within three days, as mandated by BOD 26-04. According to Fortinet, the security bug was discovered internally and affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1. The company says fixes will be included in the upcoming FortiMail versions 7.4.9, 7.6.7, and 8.0.2, but has not provided a release timeline. Neither Fortinet nor CISA has provided details on the observed attacks. Related: Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure Related: Zammad Zero-Days Exploited in AI-Powered DIVD Hack Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability Related: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Zimbra Vulnerability Exploited in the Wild Prior to Public DisclosureZammad Zero-Days Exploited in AI-Powered DIVD Hack500,000 Active Credentials Left Exposed on GitHubCisco Patches Exploited Catalyst SD-WAN Zero-Day VulnerabilityWatchGuard Patches Critical Fireware OS Code Injection VulnerabilityChrome, Firefox Updates Patch Over 100 VulnerabilitiesRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come Forward Latest News Warlock Expands SharePoint Exploitation in Critical Infrastructure AttacksAI Agents Aimed SQL Injection at US and Canadian Government SitesZero Trust Creator Says Model Holds Firm Against AI-Assisted AttacksOsavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical DomainsEnterprises Struggle to Prepare for AI and Quantum Threats, PwC SaysHacker Conversations: Rob Juncker, a Knock at the Door and a Moral CompassPolice Shut Down KillSec Ransomware, Identify Alleged Teen LeaderAI Has Changed Attack Speed, Not Security Fundamentals Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveLumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-104286