Vulnerabilities

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system.

Fortinet zero-day

The US Cybersecurity and Infrastructure Security Agency (CISA) and Fortinet on Thursday sounded the alarm on a critical FortiMail vulnerability that has been exploited in the wild. Patches have yet to be released.

Tracked as CVE-2026-104286 (CVSS score of 9.8), the zero-day is a path traversal and an improper neutralization of NULL byte or NULL character flaw that could allow attackers to write arbitrary files to the underlying system.

Threat actors could exploit the issue via crafted HTTP or HTTPS requests, potentially gaining arbitrary code or command execution.

Fortinet has published an advisory describing the security defect, urging organizations to disable the IBE feature support or disable access to the FortiMail management interface from the web and limit access to trusted sources. 

“This has been reported to be exploited in the wild; customers are urged to apply the workaround,” the company said.

Fortinet also published indicators of compromise (IoCs) to help security teams hunt for potential intrusions.

Advertisement. Scroll to continue reading.

On Thursday, CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to address it within three days, as mandated by BOD 26-04.

According to Fortinet, the security bug was discovered internally and affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1.

The company says fixes will be included in the upcoming FortiMail versions 7.4.9, 7.6.7, and 8.0.2, but has not provided a release timeline.

Neither Fortinet nor CISA has provided details on the observed attacks.

Related: Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

Related: Zammad Zero-Days Exploited in AI-Powered DIVD Hack

Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Related: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Related Content

Malware & Threats

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025.

Vulnerabilities

Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction.

Artificial Intelligence

The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root.

Vulnerabilities

The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges.

Vulnerabilities

Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772.

Mobile & Wireless

Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team.

Vulnerabilities

Citrix has released patches for the critical NetScaler vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772.

Vulnerabilities

CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version