Fortinet sounds the alarm over actively exploited FortiMail zero-day
Article excerpt
Highlighted: the sentence this signal was extracted from
security No login required, exploitation underway, and some admins are still waiting for patches Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Writing files to certain locations could allow an attacker to execute code or commands on the appliance. Fortinet says the flaw affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The vendor's advisory says CVE-2026-104286 "is being exploited in the wild," although it doesn't say when the attacks began, who is behind them, or how many customers may have been compromised. It has, however, published indicators administrators can hunt for on their systems. These include suspicious files and configuration changes, along with IP addresses associated with the attacks. CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog...
Keep reading with a free account
The rest of this article, and every signal for Fortinet, is in your free account.
