Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fortinet FortiMail mitigation guidance for CVE-2026-104286

Advisory/Mitigation
First reported
Last updated
Happening score
H score 49
1 unique sources, 1 articles

Summary

Hide ▲

Fortinet issued mitigation guidance for CVE-2026-104286 in FortiMail, warning administrators to use workarounds while the flaw is being actively exploited. The advisory tells customers to disable IBE support or restrict management access to trusted private networks until a security update is available. The guidance applies to FortiMail 7.2.0-7.2.9, 7.4.0-7.4.8, 7.6.0-7.6.6, and 8.0.0-8.0.1. Fortinet says fixed builds are coming in 7.4.9, 7.6.7, and 8.0.2, and 7.2 users can move to the 7.4 branch or later.

Related Happenings

CISA KEV mandate for FortiMail CVE-2026-104286

Public Sector Action
H score32 First: 02.10.2026 01:42 Last: 02.10.2026 01:42 Sources 1

How related: CISA has now added the CVE-2026-104286 flaw to the Known Exploited Vulnerability catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4th.

About this happening: CISA added CVE-2026-104286 to the Known Exploited Vulnerability catalog and required federal agencies to perform forensic triage and mitigate the FortiMail fla...

FortiMail actively exploited path traversal and NULL-byte flaw (CVE-2026-104286)

Vulnerability
H score43 First: 02.10.2026 01:42 Last: 02.10.2026 01:42 Sources 1

How related: Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.

About this happening: Fortinet FortiMail is facing an actively exploited CVE-2026-104286 flaw that lets unauthenticated attackers write arbitrary files and run unauthorized code on vulnerable d...

FortiSandbox unauthenticated command injection (CVE-2026-25089)

Vulnerability
H score47 First: 16.06.2026 13:30 Last: 16.06.2026 13:30 Sources 1

About this happening: CVE-2026-25089 is an unauthenticated operating system command injection in FortiSandbox-related products that was seen in active exploitation over the past 24 ho...

Latest development: 17.07.2026 10:03

CISA ordered U.S. federal agencies to prioritize patching CVE-2026-39808 and CVE-2026-25089 in Fortinet FortiSandbox after confirming both flaws are actively exploited in the wild, with vulnerable FortiSandbox instances subject to a Sunday, July 19 patch deadline under BOD 26-04.

Fortinet FortiSandbox multi-CVE exploitation wave

Exploitation Wave
H score49 First: 16.06.2026 12:19 Last: 16.06.2026 12:19 Sources 1

About this happening: Fortinet FortiSandbox is facing an active exploitation wave that puts affected deployments at risk of unauthenticated remote code execution and privilege escalat...

Fortinet security patch release for CVE-2026-39813

Security Patch Release
H score41 First: 16.06.2026 12:19 Last: 16.06.2026 12:19 Sources 1

About this happening: Fortinet released April 14 security updates for FortiSandbox, covering CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The patch release fixes three...

Latest development: 17.07.2026 12:45

CISA added CVE-2026-39808 and CVE-2026-25089, affecting Fortinet’s FortiSandbox, to its Known Exploited Vulnerabilities catalog on July 16 after warning that both critical CVSS 9.1 flaws are being exploited in the wild. The agency required US federal agencies to apply Fortinet’s mitigations and patches and urged rollout by July 19.

Timeline

  1. 02.10.2026 01:42 2 articles · 1h ago

    Fortinet warns of active zero-day exploitation in CVE-2026-104286

    Initial Disclosure

    Fortinet warns FortiMail customers that CVE-2026-104286 is a critical FortiMail management-interface flaw with a CVSS score of 9.8 that is being actively exploited in zero-day attacks to execute unauthorized code or commands, with an unauthenticated attacker able to write arbitrary files via crafted HTTP or HTTPS requests. The advisory says the issue affects FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, recommends disabling IBE feature support or restricting management access to trusted private networks, lists upcoming fixes in FortiMail 7.4.9, 7.6.7, and 8.0.2, publishes indicators of compromise tied to compromised systems, and notes that CISA added the flaw to the Known Exploited Vulnerability catalog.

    Show sources