Security advisories

FortiMail Zero-Day Vulnerability (CVE-2026-104286)

October 2, 2026

3 MINS READ

The Threat

On October 1st, 2026, Fortinet disclosed a critical zero-day vulnerability impacting multiple versions of FortiMail. Fortinet has confirmed active exploitation prior to patch disclosure.

The vulnerability, tracked as CVE-2026-104286 (CVSS: 9.8), allows unauthenticated threat actors to write arbitrary files via crafted HTTP or HTTPS requests. Exploitation allows for unauthenticated code execution on the underlying system.

At the time of writing, security patches have been released for one of the four impacted versions. As exploitation is ongoing, it is critical that organizations apply the available security patches or alternative mitigations immediately.

What we're doing about it

What you should do about it

Additional information

CVE-2026-104286 is due to a combination of a path traversal flaw and the improper neutralization of NULL bytes or NULL characters. It was discovered internally by the Fortinet Product Security team. The vulnerability is highly concerning as it could enable initial access into organizations, and a variety of other malicious actions including the deployment of additional tools. All potentially impacted devices should be reviewed for signs of compromise, as patching or applying recommended mitigations will not remove previously established persistence mechanisms. Fortinet has provided a short list of IoCs for hunting purposes.

While Fortinet states that the company is aware of reported exploitation, no additional details on real-world attacks were provided. CISA added validity to the exploitation claim on October 1st by adding CVE-2026-104286 to the Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch (FCEB) agencies have been given a short patch window, requiring remediation by October 4th.

Versions Vulnerable Fixed
FortiMail 8.0 8.0.0 - 8.0.1 8.0.2 or above (upcoming)
FortiMail 7.6 7.6.0 - 7.6.6 7.6.7 or above (upcoming)
FortiMail 7.4 7.4.0 - 7.4.8 7.4.9 or above (upcoming)
FortiMail 7.2 7.2.0 - 7.2.9 Branch 7.4 or above

References:

[1] https://fortiguard.fortinet.com/psirt/FG-IR-26-175
[2] https://www.cve.org/CVERecord?id=CVE-2026-104286
[3] https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
[4] https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories