Fortinet FortiMail mitigation guidance for CVE-2026-104286
Advisory/Mitigation
Summary
Hide ▲
Show ▼
Fortinet issued mitigation guidance for CVE-2026-104286 in FortiMail, warning administrators to use workarounds while the flaw is being actively exploited. The advisory tells customers to disable IBE support or restrict management access to trusted private networks until a security update is available. The guidance applies to FortiMail 7.2.0-7.2.9, 7.4.0-7.4.8, 7.6.0-7.6.6, and 8.0.0-8.0.1. Fortinet says fixed builds are coming in 7.4.9, 7.6.7, and 8.0.2, and 7.2 users can move to the 7.4 branch or later.
Related Happenings
CISA KEV mandate for FortiMail CVE-2026-104286
Public Sector Action
H score32
First: 02.10.2026 01:42
Last: 02.10.2026 01:42
Sources 1
How related:
CISA has now added the CVE-2026-104286 flaw to the Known Exploited Vulnerability catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4th.
About this happening:
CISA added CVE-2026-104286 to the Known Exploited Vulnerability catalog and required federal agencies to perform forensic triage and mitigate the FortiMail fla...
CISA KEV mandate for FortiMail CVE-2026-104286
Public Sector ActionHow related: CISA has now added the CVE-2026-104286 flaw to the Known Exploited Vulnerability catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4th.
About this happening: CISA added CVE-2026-104286 to the Known Exploited Vulnerability catalog and required federal agencies to perform forensic triage and mitigate the FortiMail fla...
FortiMail actively exploited path traversal and NULL-byte flaw (CVE-2026-104286)
Vulnerability
H score43
First: 02.10.2026 01:42
Last: 02.10.2026 01:42
Sources 1
How related:
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.
About this happening:
Fortinet FortiMail is facing an actively exploited CVE-2026-104286 flaw that lets unauthenticated attackers write arbitrary files and run unauthorized code on vulnerable d...
FortiMail actively exploited path traversal and NULL-byte flaw (CVE-2026-104286)
VulnerabilityHow related: Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.
About this happening: Fortinet FortiMail is facing an actively exploited CVE-2026-104286 flaw that lets unauthenticated attackers write arbitrary files and run unauthorized code on vulnerable d...
FortiSandbox unauthenticated command injection (CVE-2026-25089)
Vulnerability
H score47
First: 16.06.2026 13:30
Last: 16.06.2026 13:30
Sources 1
About this happening:
CVE-2026-25089 is an unauthenticated operating system command injection in FortiSandbox-related products that was seen in active exploitation over the past 24 ho...
FortiSandbox unauthenticated command injection (CVE-2026-25089)
VulnerabilityAbout this happening: CVE-2026-25089 is an unauthenticated operating system command injection in FortiSandbox-related products that was seen in active exploitation over the past 24 ho...
Latest development: 17.07.2026 10:03
CISA ordered U.S. federal agencies to prioritize patching CVE-2026-39808 and CVE-2026-25089 in Fortinet FortiSandbox after confirming both flaws are actively exploited in the wild, with vulnerable FortiSandbox instances subject to a Sunday, July 19 patch deadline under BOD 26-04.
Fortinet FortiSandbox multi-CVE exploitation wave
Exploitation Wave
H score49
First: 16.06.2026 12:19
Last: 16.06.2026 12:19
Sources 1
About this happening:
Fortinet FortiSandbox is facing an active exploitation wave that puts affected deployments at risk of unauthenticated remote code execution and privilege escalat...
Fortinet FortiSandbox multi-CVE exploitation wave
Exploitation WaveAbout this happening: Fortinet FortiSandbox is facing an active exploitation wave that puts affected deployments at risk of unauthenticated remote code execution and privilege escalat...
Fortinet security patch release for CVE-2026-39813
Security Patch Release
H score41
First: 16.06.2026 12:19
Last: 16.06.2026 12:19
Sources 1
About this happening:
Fortinet released April 14 security updates for FortiSandbox, covering CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The patch release fixes three...
Fortinet security patch release for CVE-2026-39813
Security Patch ReleaseAbout this happening: Fortinet released April 14 security updates for FortiSandbox, covering CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089. The patch release fixes three...
Latest development: 17.07.2026 12:45
CISA added CVE-2026-39808 and CVE-2026-25089, affecting Fortinet’s FortiSandbox, to its Known Exploited Vulnerabilities catalog on July 16 after warning that both critical CVSS 9.1 flaws are being exploited in the wild. The agency required US federal agencies to apply Fortinet’s mitigations and patches and urged rollout by July 19.
Timeline
-
02.10.2026 01:42 2 articles · 1h ago
Fortinet warns of active zero-day exploitation in CVE-2026-104286
Initial DisclosureFortinet warns FortiMail customers that CVE-2026-104286 is a critical FortiMail management-interface flaw with a CVSS score of 9.8 that is being actively exploited in zero-day attacks to execute unauthorized code or commands, with an unauthenticated attacker able to write arbitrary files via crafted HTTP or HTTPS requests. The advisory says the issue affects FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, recommends disabling IBE feature support or restricting management access to trusted private networks, lists upcoming fixes in FortiMail 7.4.9, 7.6.7, and 8.0.2, publishes indicators of compromise tied to compromised systems, and notes that CISA added the flaw to the Known Exploited Vulnerability catalog.
Show sources
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks — www.bleepingcomputer.com — 02.10.2026 01:42
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks — www.bleepingcomputer.com — 02.10.2026 01:42