Critical FortiMail Zero-Day Exploited in the Wild, CISA Adds Flaw to KEV Catalog
Fortinet is warning customers about active exploitation of a critical zero-day vulnerability in FortiMail, its email security platform. Tracked as CVE-2026-104286, the flaw carries a CVSS score of 9.8 and allows an unauthenticated attacker to write arbitrary files to the underlying system through crafted HTTP or HTTPS requests.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on October 1, citing evidence that the flaw is being exploited in the wild. Federal civilian agencies have been given until October 4 to address the vulnerability.
FortiMail Flaw Allows Unauthenticated File Writes
CVE-2026-104286 combines a path traversal vulnerability (CWE-22) with improper neutralization of NULL bytes or characters (CWE-158). An attacker does not need authentication to exploit the issue.
By sending specially crafted requests to an affected FortiMail system, an attacker can bypass restrictions on file paths and write files to the underlying operating system. Security researchers note that writing files to specific system locations could potentially lead to code or command execution.
Multiple FortiMail Versions Are Affected
Fortinet says the vulnerability affects several supported FortiMail branches:
FortiMail 8.0.0 through 8.0.1
FortiMail 7.6.0 through 7.6.6
FortiMail 7.4.0 through 7.4.8
FortiMail 7.2.0 through 7.2.9
Fixes are planned for FortiMail 8.0.2, 7.6.7 and 7.4.9, while Fortinet has advised customers to use available mitigations until the relevant security updates are released.
Fortinet Urges Immediate Mitigation
Fortinet has recommended disabling Identity-Based Encryption (IBE) functionality as a temporary mitigation and restricting access to the FortiMail management interface from the public internet. Management access should instead be limited to trusted networks where possible.
The company has also released indicators of compromise to help security teams check affected systems for signs of unauthorized activity. Fortinet says the vulnerability was discovered internally by Gwendal Guégniaud of its Product Security team.
CISA Adds Zero-Day to Known Exploited Vulnerabilities List
CISA's addition of CVE-2026-104286 to the KEV catalog reflects confirmed evidence of exploitation rather than a theoretical security risk. CISA requires U.S. federal civilian agencies to prioritize remediation of vulnerabilities listed in the catalog under its vulnerability-management directives.
CISA's deadline for this FortiMail vulnerability is October 4, 2026. The agency also recommends that organisations assess potentially exposed systems and follow vendor mitigation guidance.
Attack Details Remain Limited
Fortinet and CISA have not publicly identified the attackers behind the exploitation or disclosed how many FortiMail systems have been compromised. The available reporting confirms exploitation in the wild but does not establish the scale or objectives of the attacks.
With patches still pending for several affected versions, organisations running vulnerable FortiMail installations are being urged to apply Fortinet's workarounds, restrict management access and investigate systems for possible compromise.
