The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiMail vulnerability, identified as CVE-2026-104286, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, which carries a CVSS score of 9.8, is a path traversal vulnerability that attackers are reportedly exploiting in the wild.
The vulnerability allows an unauthenticated attacker to write arbitrary files to the underlying system by sending specially crafted HTTP or HTTPS requests. This is possible due to an improper limitation of a pathname to a restricted directory (CWE-22) combined with an improper neutralization of NULL byte or NULL character (CWE-158). The inclusion of NULL characters can help attackers bypass security checks.
Fortinet has confirmed the existence of the vulnerability and its active exploitation. However, the company has not disclosed details regarding the number of affected customers, the start date of the attacks, the identities of the attackers, or specific technical aspects of the exploits.
Affected FortiMail versions include 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, and 7.4.0 through 7.4.8. Fortinet recommends upgrading to upcoming versions 8.0.2, 7.6.7, or 7.4.9, respectively, once they are released. Users on FortiMail 7.2.0 through 7.2.9 are advised to upgrade to the 7.4 branch or above.
As temporary mitigation, Fortinet suggests disabling the Identity-Based Encryption (IBE) feature using a recommended command-line interface (CLI) command. Alternatively, access to the FortiMail management interface should be blocked from the internet or restricted to trusted private networks.
Under CISA's Binding Operational Directive (BOD) 22-01, federal civilian executive branch (FCEB) agencies are mandated to address vulnerabilities listed in the KEV catalog by a specified due date to protect their networks. CISA has set a deadline of October 3rd, 2026, for federal agencies to remediate this particular FortiMail flaw. Private organizations are also strongly encouraged to review the catalog and address these vulnerabilities within their own infrastructure.






