Fortinet is warning that attackers are actively exploiting CVE-2026-104286, a zero-day path traversal flaw in FortiMail that can let an unauthenticated attacker write arbitrary files through crafted HTTP or HTTPS requests. CISA has added the issue to its KEV catalog, and Fortinet is urging customers to apply workarounds and check the shared indicators while waiting for patches. #Fortinet #FortiMail #CVE-2026-104286 #CISA #GwendalGuégniaud
Keypoints
- CVE-2026-104286 is being exploited in the wild against FortiMail.
- The flaw allows arbitrary file writes through crafted HTTP or HTTPS requests.
- CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.
- Fortinet advises disabling IBE or restricting management access as a workaround.
- FortiMail versions 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9 are affected.
Read More: https://www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-104286/