Skip to main content
FortinetSecurity incident

Fortinet sounds the alarm over actively exploited FortiMail zero-day

What happened

Fortinet's FortiMail email security platform has a critical zero-day vulnerability (CVE-2026-104286) that is being actively exploited, allowing unauthenticated attackers to write arbitrary files to vulnerable systems.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

security No login required, exploitation underway, and some admins are still waiting for patches Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Writing files to certain locations could allow an attacker to execute code or commands on the appliance. Fortinet says the flaw affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The vendor's advisory says CVE-2026-104286 "is being exploited in the wild," although it doesn't say when the attacks began, who is behind them, or how many customers may have been compromised. It has, however, published indicators administrators can hunt for on their systems. These include suspicious files and configuration changes, along with IP addresses associated with the attacks. CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog...

Keep reading with a free account

The rest of this article, and every signal for Fortinet, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Product
FortiMail

More security incident signals at other companies

The full record

From the Signal API record

Details

Issue named
A critical zero-day vulnerability (CVE-2026-104286) in FortiMail's web interface, involving path traversal and improper handling of null characters, is being actively exploited in the wild, allowing unauthenticated attackers to write...

Topics and mentions

Product tags

  • online technology
  • general technology
  • security

Extraction

Confidence
100%
Detected
Oct 2, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for Fortinet and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Fortinet this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/5f657745-cb9e-c31c-f7a2-89fa456ba8da returns this record as JSON. POST /v1/companies/enrich returns every signal for fortinet.com.

{
  "signal_id": "5f657745-cb9e-c31c-f7a2-89fa456ba8da",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-10-02T10:53:49+00:00",
  "company": {
    "name": "Fortinet",
    "domain": "fortinet.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/5300803",
    "title": "Fortinet sounds the alarm over actively exploited FortiMail zero-day",
    "excerpt": "security No login required, exploitation underway, and some admins are still waiting for patches Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Writing files to certain locations could allow an attacker to execute code or commands on the appliance. Fortinet says the flaw affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The vendor's advisory says CVE-2026-104286 \"is being exploited in the wild,\" although it doesn't say when the attacks began, who is behind them, or how many customers may have been compromised. It has, however, published indicators administrators can hunt for on their systems. These include suspicious files and configuration changes, along with IP addresses associated with the attacks. CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog...",
    "product": "FortiMail",
    "summary": "Fortinet's FortiMail email security platform has a critical zero-day vulnerability (CVE-2026-104286) that is being actively exploited, allowing unauthenticated attackers to write arbitrary files to vulnerable systems.",
    "planning": false,
    "image_url": "https://image.theregister.com/5300807.jpg?imageId=5300807&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 1,
    "product_data": {
      "name": "FortiMail",
      "full_text": "Fortinet's email security platform",
      "fuzzy_match": false
    },
    "product_tags": [
      "online_technology",
      "general_technology",
      "security"
    ],
    "published_at": "2026-10-02T10:53:49Z",
    "vulnerability": "A critical zero-day vulnerability (CVE-2026-104286) in FortiMail's web interface, involving path traversal and improper handling of null characters, is being actively exploited in the wild, allowing unauthenticated attackers to write arbitrary files to the system via specially crafted HTTP or HTTPS requests.",
    "article_sentence": "Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.