Fortinet has issued a warning regarding a critical vulnerability in its FortiMail email security platform, identified as CVE-2026-104286, which is actively being exploited in zero-day attacks. The flaw, rated with a CVSS score of 9.8, affects the FortiMail management interface and could allow an unauthenticated attacker to execute arbitrary code or commands.
The vulnerability is described as a path traversal and an improper neutralization of NULL byte or NULL character flaw. This combination may allow an unauthenticated attacker to write arbitrary files on the underlying system by sending crafted HTTP or HTTPS requests.
CVE-2026-104286 was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on October 1, 2026, the same day it was publicly disclosed. This immediate inclusion indicates that the vulnerability was exploited in the wild as a zero-day.
Multiple authoritative sources, including the CISA KEV, the European Union Agency for Cybersecurity (ENISA) KEV, and VulnCheck KEV, all listed the vulnerability as exploited on October 1, 2026. This strong consensus from three independent catalogs confirms the active exploitation.
Fortinet's own security advisory, FG-IR-26-175, also reported exploitation of the vulnerability on October 1, 2026, further corroborating the claims from the KEV catalogs.
CISA has issued a directive requiring federal agencies to apply mitigations in accordance with vendor instructions by October 4, 2026. The directive emphasizes compliance with CISA's BOD 26-04 guidance, which prioritizes security updates based on risk, and its "Forensics Triage Requirements."
For cloud services, CISA advises stakeholders to evaluate each asset's internet exposure and ensure adherence to patching guidelines. If mitigations are unavailable, discontinuing the use of the affected product is recommended.
The rapid exploitation of this vulnerability highlights the ongoing challenge of securing critical infrastructure against sophisticated threats, particularly when flaws are exploited on the very day of their public disclosure.






