Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet said the 9.8-rated flaw lets unauthenticated attackers write files on affected FortiMail appliances and could enable code execution.
- Fortinet warned customers of a critical vulnerability, CVE-2026-104286, currently being exploited in the wild with a CVSS score of 9.8 that allows unauthenticated attackers to write arbitrary files via HTTP or HTTPS requests.
- The vulnerability stems from path traversal and improper null character handling in FortiMail's web interface, affecting versions 8.0, 7.6, 7.4, and 7.2 and potentially enabling code execution on affected appliances.
- CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, directing US federal civilian agencies to apply mitigations by October 4; Fortinet lists fixes as "upcoming," leaving customers reliant on workarounds.
- Administrators must check for signs of compromise, including suspicious files and configuration changes, because applying workarounds will not remove existing persistence mechanisms attackers may have planted.
- This incident follows other security challenges for Fortinet this year; in June, credentials linked to around 75,000 FortiGate firewalls surfaced, though Fortinet attributed the data to brute-force attacks rather than a fresh breach.
17 Articles
17 Articles
FortiMail Zero-Day Exploited in Attacks, CISA Warns
FortiMail Zero-Day Exploited in Attacks, CISA Adds Flaw to KEV Catalogue Published on 02/10/2026 12:28 PM Nanette le Roux Fri, 10/02/2026 - 09:54 A critical zero-day vulnerability in Fortinet’s FortiMail email security platform is being actively exploited and this has prompted a warning from the US Cybersecurity and Infrastructure Security Agency (CISA). Fortinet is a major cybersecurity provider used by organisations worldwide, while FortiMail …
Fortinet flags actively exploited FortiMail zero-day
Fortinet says CVE-2026-104286, a critical FortiMail flaw rated 9.8, is under active exploitation. The bug combines path traversal with null-character handling issues in the web interface, allowing unauthenticated attackers to write arbitrary files via...
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]
The INCIBE-CERT has warned of a critical vulnerability in FortiMail de Fortinet that the attackers are actively exploiting. The alert, published on Friday, October 2, 2026 with the INCIBE-2026-692 identifier, affects one of the most widely used email gateways by companies and public administrations. The bug allows an unauthenticated remote attacker to write arbitrary files on the affected system and, from there, execute unauthorized code or comm…
Coverage Details
Bias Distribution
- 80% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium













