Fortinet reports active exploitation of critical FortiMail zero-day
Fortinet says attackers are exploiting CVE-2026-104286, a path-traversal and null-byte flaw that could let an unauthenticated attacker write arbitrary files through crafted HTTP or HTTPS requests. It affects specified FortiMail 7.2, 7.4, 7.6 and 8.0 releases; fixes are not yet available, and Fortinet advises disabling identity-based encryption or restricting access to the management interface as temporary mitigations. The company has not disclosed when or where attacks occurred, how many systems were compromised, or who was responsible.
Why it matters FortiMail administrators face an interim operational trade-off: disable identity-based encryption or limit management access while waiting for a patch.
What to watch next US federal civilian agencies must address the vulnerability by October 4, 2026. That is a remediation deadline, not a promised patch-release date.
HelpNet Security ↗