Critical FortiMail Zero-Day CVE-2026-104286 Exploited in the Wild

www.news4hackers.com-critical-fortimail-zero-day-cve-2026-104286-exploited-in-the-wild-critical-fortimail-zero-day-cve-2026-104286-exploited-in-the-wild

Critical vulnerability CVE-2026-104286 in FortiMail is actively exploited, requiring immediate mitigation measures.

Vulnerability Overview

Fortinet has issued an urgent alert regarding active exploitation of a critical vulnerability (CVE-2026-104286) in its FortiMail security gateway. The flaw, which enables unauthorized file writes on affected systems, has been confirmed to be actively targeted by threat actors. The company has released temporary mitigation measures while final patches remain pending.

Details of the Flaw

The vulnerability arises from improper handling of pathname restrictions and null byte neutralization, classified under CWE-22 and CWE-158. Attackers can exploit this through crafted HTTP or HTTPS requests to execute arbitrary file writes on the underlying operating system. A security advisory published on October 1, 2026, details the flaw, which received immediate inclusion in the US Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) list.

Severity and Affected Versions

The flaw carries a CVSSv3 score of 9.8, reflecting its high severity. Discovered internally by Gwendal Guégniaud of Fortinet’s Product Security team, the vulnerability impacts FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.

Mitigation Measures

Patches are scheduled for release in versions 8.0.2, 7.6.7, and 7.4.9, with users of the 7.2.x branch advised to migrate to the 7.4 branch or higher. To mitigate risks before official updates, administrators are instructed to disable FortiMail’s identity-based encryption (IBE) feature using the following command sequence: config system encryption ibe set status disable end. Alternative measures include restricting management interface access to trusted private networks or blocking external internet connectivity to the device.

Indicators of Compromise

Fortinet has also provided indicators of compromise, including specific files, IP addresses, and log patterns, to assist in detecting potential breaches.

Additional Information

No information has been disclosed regarding the geographic scope of attacks, the number of affected systems, or the identities of the actors involved. The company has not confirmed whether the vulnerability was exploited prior to its public disclosure.

Federal civilian agencies are required to resolve the issue by October 4, 2026.

Conclusion

The incident underscores the urgency of applying available workarounds and monitoring systems for signs of unauthorized activity. Enterprises utilizing affected FortiMail versions are encouraged to prioritize mitigation steps to prevent potential data exposure or system compromise.


Blog Image

About Author

en_USEnglish