Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

A Critical Zero-Day Flaw in FortiMail Exposes Organizations Worldwide

The US Cybersecurity and Infrastructure Security Agency (CISA) has sounded the alarm on a critical vulnerability in Fortinet’s FortiMail email security solution. The zero-day flaw, tracked as CVE-2026-104286 with a CVSS score of 9.8, allows attackers to write arbitrary files to the underlying system by exploiting a path traversal and improper neutralization of NULL byte or NULL character flaw.

This vulnerability has already been exploited in the wild, and Fortinet is urging customers to take immediate action to protect themselves. The company has published an advisory recommending that organizations disable the IBE feature support or limit access to the FortiMail management interface from the web and restrict it to trusted sources only. Additionally, Fortinet has released indicators of compromise (IoCs) to help security teams detect potential intrusions.

The vulnerability affects multiple versions of FortiMail, including 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1. Although Fortinet has not provided a release timeline for patches, they have confirmed that fixes will be included in upcoming versions of the software.

CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog and is urging federal agencies to address the issue within three days, as mandated by BOD 26-04. The fact that this vulnerability has already been exploited in the wild highlights the importance of prioritizing patching and taking proactive measures to prevent attacks.

Organizations relying on FortiMail should take immediate action to protect themselves. This includes disabling IBE feature support or limiting access to the management interface from the web, as well as restricting it to trusted sources only. Additionally, security teams should be on high alert for potential intrusions and review system logs for signs of suspicious activity.

The exploitation of this zero-day flaw underscores the need for organizations to maintain a robust cybersecurity posture, including regular patching, monitoring, and incident response planning. By taking proactive measures to address vulnerabilities and staying informed about emerging threats, organizations can reduce their risk exposure and stay ahead of attackers.


Source: SecurityWeek — 2026-10-02