← All articles

Fortinet FortiMail zero-day under active exploitation allows unauthenticated arbitrary file writes

CISA added a critical FortiMail flaw to its Known Exploited Vulnerabilities catalog after reports of active exploitation. Tracked as CVE-2026-104286 and rated 9.8, it combines a path traversal with improper NULL byte neutralization, letting an unauthenticated attacker write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. Fortinet confirmed in-the-wild exploitation. Affected versions are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, with fixed builds coming in the 8.0.2, 7.6.7, and 7.4.9 releases and a move off 7.2 to branch 7.4. Until fixes land for some versions, Fortinet recommends disabling IBE feature support and restricting access to the administrative interface.

Check
Identify internet-facing FortiMail appliances, apply the fixed release for your branch when available, and meanwhile disable IBE and restrict the admin interface.
Affected
FortiMail versions in the affected ranges let an unauthenticated attacker write arbitrary files via crafted web requests, and exploitation is already occurring.
Fix
Upgrade to the fixed FortiMail builds, apply the IBE and admin-access workarounds in the interim, and review hosts for unexpected written files.