Back
Critical FortiMail zero-day exploited in attacks, CISA adds CVE-2026-104286 to KEV
SiTech AI Team2 min read

Critical FortiMail zero-day exploited in attacks, CISA adds CVE-2026-104286 to KEV

CISA added CVE-2026-104286, a critical FortiMail flaw with a CVSS score of 9.8, to its Known Exploited Vulnerabilities catalog after reports of active exploitation. The bug lets unauthenticated attackers write arbitrary files on the system.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Fortinet FortiMail vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, following reports of active exploitation. Tracked as CVE-2026-104286, the flaw carries a CVSS score of 9.8 and allows unauthenticated attackers to write arbitrary files on the underlying system.

What the vulnerability allows

According to Fortinet's advisory, the bug combines an improper limitation of a pathname to a restricted directory (path traversal, CWE-22) with improper neutralization of a NULL byte or NULL character (CWE-158). Together, they let an unauthenticated attacker write arbitrary files on the underlying system through crafted HTTP or HTTPS requests.

The affected versions are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9. Fortinet's guidance is to upgrade to the upcoming 8.0.2, 7.6.7 or 7.4.9 releases, or above; systems on the 7.2 branch should move to 7.4 or later. Until those fixes are available, the company recommends interim workarounds.

Workarounds and indicators of compromise

Fortinet urges customers to disable IBE feature support through the relevant CLI command and to restrict access to the FortiMail management interface, blocking it from the internet and allowing connections only from trusted private networks. The company acknowledged that the flaw has been exploited in the wild and credited Gwendal Guégniaud of its Product Security team with discovering and reporting it.

Fortinet also published indicators of compromise: the IP addresses 79.141.169.187 and 45.129.0.192, files added under /data (including /data/lib/liblog.so and /data/etc/ld.so.preload), and a modified /bin/smit. Federal Civilian Executive Branch (FCEB) agencies are advised to apply the patch or workarounds by October 4, 2026.

A wider wave of exploitation

The FortiMail case is not isolated: active exploitation is also being tracked in several other enterprise products. These include Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772).

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.