Fortinet warns of exploited FortiMail zero-day affecting multiple releases
Fortinet says attackers are exploiting CVE-2026-104286, an unauthenticated path-traversal and NULL-byte flaw that can allow arbitrary file writes through crafted HTTP or HTTPS requests. The vulnerability affects specified FortiMail 7.2, 7.4, 7.6 and 8.0 releases; fixes are pending. Until then, Fortinet recommends disabling identity-based encryption or restricting access to the management interface, and says it has shared indicators to help customers check for compromise.
Why it matters FortiMail administrators face an immediate mitigation decision rather than a routine patch rollout: fixed releases are unavailable, and users on 7.2 are directed to move to a newer branch.
What to watch next Watch for the promised fixed releases. Separately, the reported October 4 federal remediation deadline falls before any patch availability date established by this source.
HelpNet Security ↗