FortiMail actively exploited path traversal and NULL-byte flaw (CVE-2026-104286)
Vulnerability
Summary
Hide ▲
Show ▼
Fortinet FortiMail is facing an actively exploited CVE-2026-104286 flaw that lets unauthenticated attackers write arbitrary files and run unauthorized code on vulnerable devices. The issue affects the FortiMail management interface and combines path traversal with NULL-byte handling weaknesses. Fortinet says the bug impacts 7.2.0-7.2.9, 7.4.0-7.4.8, 7.6.0-7.6.6, and 8.0.0-8.0.1. Customers are being told to use workarounds now while fixes roll out in 7.4.9, 7.6.7, and 8.0.2.
Related Happenings
Fortinet FortiMail mitigation guidance for CVE-2026-104286
Advisory/Mitigation
H score49
First: 02.10.2026 01:42
Last: 02.10.2026 01:42
Sources 1
How related:
Fortinet says the flaw is being actively exploited and is urging customers to apply the shared workarounds until a security update can be installed.
About this happening:
Fortinet issued mitigation guidance for CVE-2026-104286 in FortiMail, warning administrators to use workarounds while the flaw is being actively exploited. The adv...
Fortinet FortiMail mitigation guidance for CVE-2026-104286
Advisory/MitigationHow related: Fortinet says the flaw is being actively exploited and is urging customers to apply the shared workarounds until a security update can be installed.
About this happening: Fortinet issued mitigation guidance for CVE-2026-104286 in FortiMail, warning administrators to use workarounds while the flaw is being actively exploited. The adv...
CISA KEV mandate for FortiMail CVE-2026-104286
Public Sector Action
H score32
First: 02.10.2026 01:42
Last: 02.10.2026 01:42
Sources 1
How related:
CISA has now added the CVE-2026-104286 flaw to the Known Exploited Vulnerability catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4th.
About this happening:
CISA added CVE-2026-104286 to the Known Exploited Vulnerability catalog and required federal agencies to perform forensic triage and mitigate the FortiMail fla...
CISA KEV mandate for FortiMail CVE-2026-104286
Public Sector ActionHow related: CISA has now added the CVE-2026-104286 flaw to the Known Exploited Vulnerability catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4th.
About this happening: CISA added CVE-2026-104286 to the Known Exploited Vulnerability catalog and required federal agencies to perform forensic triage and mitigate the FortiMail fla...
Fortinet FortiSandbox multi-CVE exploitation wave
Exploitation Wave
H score49
First: 16.06.2026 12:19
Last: 16.06.2026 12:19
Sources 1
About this happening:
Fortinet FortiSandbox is facing an active exploitation wave that puts affected deployments at risk of unauthenticated remote code execution and privilege escalat...
Fortinet FortiSandbox multi-CVE exploitation wave
Exploitation WaveAbout this happening: Fortinet FortiSandbox is facing an active exploitation wave that puts affected deployments at risk of unauthenticated remote code execution and privilege escalat...
Timeline
-
02.10.2026 01:42 2 articles · 1h ago
Fortinet warns of actively exploited FortiMail CVE-2026-104286
Initial DisclosureFortinet warned customers that CVE-2026-104286 in FortiMail is being actively exploited in zero-day attacks against the management interface, where an unauthenticated attacker can write arbitrary files via crafted HTTP or HTTPS requests and execute unauthorized code or commands on vulnerable devices. The advisory covers FortiMail 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1, says fixes for some branches are still pending, recommends disabling IBE feature support or restricting management-interface access, and includes indicators of compromise while Fortinet coordinates with CISA after the flaw was added to the Known Exploited Vulnerability catalog.
Show sources
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks — www.bleepingcomputer.com — 02.10.2026 01:42
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks — www.bleepingcomputer.com — 02.10.2026 01:42