started · updated
Fortinet FortiMail zero-day vulnerability actively exploited
A critical zero-day vulnerability, identified as CVE-2026-104286, is being actively exploited in Fortinet’s FortiMail email security appliances. The flaw, which carries a CVSS score of 9.8, involves a combination of path traversal (CWE-22) and improper null byte neutralization (CWE-158) within the Identity-Based Encryption (IBE) GUI component.
Unauthenticated attackers can use crafted HTTP or HTTPS requests to write arbitrary files to the underlying operating system. Because the vulnerability exists in the management interface, attackers can potentially compromise the system without valid credentials. Affected versions include FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.
As of the disclosure, no official patches are available for the 7.4, 7.6, or 8.0 branches, though Fortinet has announced upcoming fixed versions. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog. Immediate mitigations include disabling the IBE feature via the command line interface or blocking internet access to the management interface. Indicators of compromise have shown attackers using the flaw to route archived email data to external servers.