CISA added a critical FortiMail flaw to its Known Exploited Vulnerabilities catalog after reports of active exploitation. Tracked as CVE-2026-104286 and rated 9.8, it combines a path traversal with improper NULL byte neutralization, letting an unauthenticated attacker write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. Fortinet confirmed in-the-wild exploitation. Affected versions are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, with fixed builds coming in the 8.0.2, 7.6.7, and 7.4.9 releases and a move off 7.2 to branch 7.4. Until fixes land for some versions, Fortinet recommends disabling IBE feature support and restricting access to the administrative interface.