Fortinet warns of critical FortiMail zero-day exploited in the wild
TLDR
- Fortinet is warning that a critical FortiMail vulnerability, CVE-2026-104286 (CVSS 9.8), is being actively exploited in zero-day attacks against the appliance's management interface.
- The path-traversal and null-byte flaw lets an unauthenticated attacker write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
- Fixed versions aren't yet available for most affected branches; Fortinet is urging workarounds, including disabling the IBE feature or restricting internet access to the management interface.
- CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, directing federal civilian agencies to prioritise remediation under its vulnerability management directive.
Fortinet's Product Security team, which discovered the flaw internally, said CVE-2026-104286 is an improper limitation of a pathname combined with improper handling of null-byte characters that may let an unauthenticated attacker write arbitrary files on the underlying system through crafted requests to the FortiMail management interface.1 The flaw affects FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.1 Only FortiMail 7.2 users currently have a fix path, by upgrading to the 7.4 branch; patched releases for the 7.4, 7.6 and 8.0 branches are still pending as of Fortinet's advisory.1
Until patches ship, Fortinet is telling administrators to disable the IBE (identity-based encryption) feature via the CLI, or to restrict access to the management interface from the internet entirely.1 The company published indicators of compromise, including modified system binaries and two attacker IP addresses, 79.141.169.187 and 45.129.0.192, along with log signatures administrators can use to check whether their appliances have already been targeted.1 CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on 1 October, citing evidence of active exploitation, and directed federal civilian agencies to prioritise remediation under its binding vulnerability management directive even though Fortinet has not yet shipped a complete fix.2
Why it matters: CISA ordering remediation before Fortinet has even finished shipping patches for three of the four affected branches signals how urgently it is treating this one, so FortiMail admins should apply the workarounds now rather than wait for an update.