THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a Fortinet FortiMail flaw to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, CVE-2026-104286, is a path traversal issue (CWE-22) that can be triggered by specially crafted HTTP or HTTPS requests, potentially allowing an unauthenticated attacker to write arbitrary files to the underlying FortiMail system.
The advisory notes that the flaw also involves improper handling of NULL characters (CWE-158), which can help bypass security checks. Fortinet states the vulnerability is being exploited in the wild, and affected customers are urged to apply the recommended workaround or vendor fixes.
FortiMail versions affected are FortiMail 8.0 (8.0.0 through 8.0.1), FortiMail 7.6 (7.6.0 through 7.6.6), FortiMail 7.4 (7.4.0 through 7.4.8), and FortiMail 7.2 (7.2.0 through 7.2.9). Upgrades are advised to FortiMail 8.0.2 or above for the 8.0 branch, 7.6.7 or above for 7.6, 7.4.9 or above for 7.4, and the 7.4+ branch for 7.2 users.
As a temporary mitigation, Fortinet recommends disabling the IBE (Identity-Based Encryption) feature via CLI, or restricting management interface access to the internet or to trusted private networks.
CISA requires federal agencies to fix the vulnerability by 3 October 2026 under Binding Operational Directive 22-01, with private organisations likewise urged to review the KEV catalog and apply fixes. The article notes that the exact impact, exploitation scope and affected user count have not been disclosed.