FORTINET’S FortiMail has a critical zero-day vulnerability being exploited in the wild, tracked as CVE-2026-104286 with a CVSS score of 9.8. The flaw is a path traversal and improper neutralisation of NULL byte/NULL character, which could allow attackers to write arbitrary files to the underlying system. Exploitation is possible via crafted HTTP or HTTPS requests, potentially enabling arbitrary code or command execution.
Fortinet and CISA have issued advisories and alerts urging immediate mitigations while patches are prepared. Fortinet’s guidance recommends disabling the IBE feature support or restricting access to the FortiMail management interface from the web and limiting access to trusted sources. The company has also published indicators of compromise to aid detection. CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog, pressuring federal agencies to address it within three days under BOD 26-04.
Fortinet lists affected FortiMail versions as 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1. Fixes are planned for FortiMail versions 7.4.9, 7.6.7, and 8.0.2, though a release timeline has not been provided. As observed attacks have not been detailed publicly, Fortinet and CISA emphasise applying the workaround and monitoring with IoCs to detect potential intrusions while organisations await patched builds.