The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added a grave security flaw affecting Fortinet’s FortiMail to its Known Exploited Vulnerabilities (KEV) list. This decision follows reports indicating the vulnerability is currently being exploited in the wild.
Details of the FortiMail Vulnerability
Identified as CVE-2026-104286 with a CVSS score of 9.8, this flaw permits unauthenticated attackers to execute arbitrary file writes on the affected systems. Fortinet’s advisory highlights that the vulnerability arises from a path traversal issue and improper neutralization of NULL bytes, which could be exploited via crafted HTTP or HTTPS requests.
The affected FortiMail versions include 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, and 7.4.0 to 7.4.8. Fortinet advises upgrading to versions 8.0.2, 7.6.7, and 7.4.9 or above when they become available.
Immediate Recommendations and Workarounds
To mitigate the risk until patches are released, Fortinet recommends disabling the IBE feature and limiting access to the FortiMail management interface to trusted networks. The specific CLI command to disable IBE is provided in their guidance.
Fortinet credits Gwendal Guégniaud from their Product Security team for identifying the vulnerability. They have also shared indicators of compromise, including specific IP addresses and modified files, to assist in detection and response efforts.
Broader Security Concerns
Federal Civilian Executive Branch (FCEB) agencies have been urged to apply recommended patches or workarounds by October 4, 2026. This urgency is underscored by the concurrent exploitation of other vulnerabilities in products from Check Point, Arista, F5, Cisco, and Citrix, as noted in various security advisories.
The rapid escalation of these exploits highlights the critical need for organizations to prioritize patch management and implement robust cybersecurity defenses.
As the cybersecurity landscape continues to evolve, staying informed and proactive is essential to safeguarding enterprise systems from emerging threats.
