Fortinet FortiMail Zero-Day Vulnerability Exploited – Urgent Action Required
Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action CISA and Fortinet issued an urgent warning regarding a critical vulnerability in FortiMail that is currently being exploited by threat actors. No patches have been made available at this time.
Urgent Warning from CISA and Fortinet
Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action CISA and Fortinet issued an urgent warning regarding a critical vulnerability in FortiMail that is currently being exploited by threat actors. No patches have been made available at this time.
Vulnerability Details
The vulnerability, designated as CVE-2026-104286 with a CVSS score of 9.8, involves a path traversal issue combined with a failure to properly neutralize NULL bytes or characters. This flaw could enable attackers to write arbitrary files to the system. Attackers may exploit this vulnerability by sending specially crafted HTTP or HTTPS requests, which could lead to arbitrary code execution or command injection.
Mitigation Recommendations
Fortinet released a security advisory outlining the flaw, recommending that organizations disable the IBE feature or restrict access to the FortiMail management interface to trusted networks. The company emphasized that the vulnerability is actively being used in attacks and advised customers to implement the recommended mitigation measures. Additionally, Fortinet provided indicators of compromise to assist security teams in identifying potential breaches.
CISA’s Involvement
CISA included CVE-2026-104286 in its Known Exploited Vulnerabilities catalog on Thursday, requiring federal agencies to remediate the issue within three days under BOD 26-04.
Affected Versions and Patches
The vulnerability was identified internally by Fortinet and impacts FortiMail versions 7.2.0 to 7.2.9, 7.4.0 to 7.4.8, 7.6.0 to 7.6.6, and 8.0.0 to 8.0.1. Fortinet stated that the necessary patches will be included in future releases, specifically versions 7.4.9, 7.6.7, and 8.0.2, though no specific release dates have been announced.
Attack Details
Both Fortinet and CISA have not disclosed specific details about the attacks exploiting this vulnerability.
