A critical zero-day vulnerability in Fortinet’s FortiMail email security platform is being actively exploited in real-world attacks, according to Fortinet and the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The flaw is tracked as CVE-2026-104286 and carries a CVSS score of 9.8, placing it in the critical severity category. It affects the FortiMail management interface and can be exploited without requiring authentication. Attackers can send specially crafted HTTP or HTTPS requests to abuse the vulnerable system.
The vulnerability involves two security weaknesses: path traversal, classified as CWE-22, and improper handling of NULL bytes or NULL characters, classified as CWE-158. Together, these issues can allow an unauthenticated attacker to bypass restrictions placed on file paths. The attacker can then write arbitrary files onto the underlying FortiMail system. Fortinet has confirmed that the vulnerability has already been exploited in the wild. The company has therefore urged customers to apply the recommended workaround while fixes become available.
The affected versions cover several FortiMail release branches currently in use. FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, and 7.4.0 through 7.4.8 are affected by the vulnerability. FortiMail 7.2.0 through 7.2.9 is also affected, with Fortinet directing users on that branch to move to the 7.4 branch or later. Fortinet has listed versions 8.0.2, 7.6.7 and 7.4.9 as the upcoming releases containing fixes.
Until the relevant updates are available, Fortinet has provided workarounds to reduce the risk of exploitation. Customers can disable Identity-Based Encryption, known as IBE, through the FortiMail command-line interface. Another option is to disable internet access to the FortiMail management interface or restrict access to trusted private networks. These measures are intended to reduce the attack surface while organizations wait for the applicable security updates.
Fortinet credited Gwendal Guégniaud from its Product Security team with discovering and reporting the vulnerability internally. The company has also published indicators of compromise to help security teams investigate potentially affected systems. Two IP addresses associated with the reported activity are 79.141.169[.]187 and 45.129.0[.]192. Fortinet also identified several files that may have been added or modified on compromised appliances.
The reported file indicators include /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice and /data/etc/ld.so.preload as added files. Other paths, including /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz, were reported as modified. Security teams can use these indicators while reviewing FortiMail systems for signs of compromise. However, Fortinet has not publicly disclosed how many systems have been compromised or who is responsible for the attacks.
CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog after reports confirmed exploitation in the wild. The addition means the vulnerability has been recognized as an actively exploited security issue rather than only a theoretical weakness. U.S. federal civilian agencies have been directed to address the vulnerability through a patch or available mitigation by October 4, 2026. Other organizations using affected FortiMail versions are also being urged to review their exposure and apply Fortinet’s recommended protections.
The FortiMail issue highlights the risk created when vulnerabilities in internet-accessible security appliances are exploited before permanent fixes are available. Because the flaw does not require authentication and can allow arbitrary files to be written to the underlying system, affected organizations should treat the situation as an active security concern. Administrators should check their FortiMail versions, restrict management-interface exposure and review the published indicators for possible compromise. Fortinet’s advisory remains the primary source for the affected versions, workarounds and indicators as the response develops.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news