Fortinet disclosed CVE-2026-104286, a critical CVSS 9.8 zero-day in the FortiMail management interface that is under active exploitation. The path-traversal and improper null-byte-neutralization flaw allows an unauthenticated remote attacker to send crafted HTTP or HTTPS requests that write arbitrary files to the underlying appliance, potentially enabling code execution, command execution, system compromise, or service disruption. Affected versions are FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9; fixes for most affected branches were not yet available when the advisory was issued.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and required U.S. federal civilian agencies to perform forensic triage and mitigate it by October 4, 2026, although no known ransomware use was identified. Organizations should identify exposed FortiMail appliances, immediately restrict management-interface access to trusted private networks, disable Identity-Based Encryption (IBE) support where feasible, apply fixed releases as they become available, and review Fortinet-provided file, IP, and log indicators for evidence of compromise.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
CISA added the actively exploited Fortinet FortiMail vulnerability CVE-2026-104286 to its Known Exploited Vulnerabilities Catalog. It required forensic triage and directed affected federal civilian agencies to mitigate the vulnerability under BOD 26-04 guidance.
Fortinet disclosed CVE-2026-104286, a critical CVSS 9.8 FortiMail management-interface flaw that combines path traversal and null-byte handling weaknesses. Unauthenticated attackers can use crafted HTTP or HTTPS requests to write arbitrary files, potentially enabling code execution; Fortinet advised disabling IBE or restricting management access and published compromise indicators.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcerunzero.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.