Skip to content
Exploited Fortinet FortiMail Zero

Exploited Fortinet FortiMail Zero

Securityweek •Ionut Arghire • October 2, 2026

The US Cybersecurity and Infrastructure Security Agency (CISA) and Fortinet on Thursday sounded the alarm on a critical FortiMail vulnerability that has been exploited in the wild. Patches have yet to be released.

Tracked as CVE-2026-104286 (CVSS score of 9.8), the zero-day is a path traversal and an improper neutralization of NULL byte or NULL character flaw that could allow attackers to write arbitrary files to the underlying system.

Threat actors could exploit the issue via crafted HTTP or HTTPS requests, potentially gaining arbitrary code or command execution.

Fortinet has published an advisory describing the security defect, urging organizations to disable the IBE feature support or disable access to the FortiMail management interface from the web and limit access to trusted sources.

“This has been reported to be exploited in the wild; customers are urged to apply the workaround,” the company said.

Fortinet also published indicators of compromise (IoCs) to help security teams hunt for potential intrusions.

On Thursday, CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities ( KEV ) catalog, urging federal agencies to address it within three days, as mandated by BOD 26-04.

According to Fortinet, the security bug was discovered internally and affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1.

The company says fixes will be included in the upcoming FortiMail versions 7.4.9, 7.6.7, and 8.0.2, but has not provided a release timeline.

Neither Fortinet nor CISA has provided details on the observed attacks.

Related: Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

Related: Zammad Zero-Days Exploited in AI-Powered DIVD Hack

Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Related: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

Zammad Zero-Days Exploited in AI-Powered DIVD Hack

500,000 Active Credentials Left Exposed on GitHub

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

Chrome, Firefox Updates Patch Over 100 Vulnerabilities

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

ShinyHunters Defiant After FBI Calls on Members to Come Forward

Reco Raises $55 Million for Agentic Security

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

AI Has Changed Attack Speed, Not Security Fundamentals

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation

Flipboard Whatsapp Whatsapp Email

Extracted Entities

APT Groups (1)

CWE Weaknesses (1)

Ransomware Groups (1)