Skip to content
feed: live
>_0dayNews
fortinet
● Breaking

Fortinet FortiMail Zero-Day CVE-2026-104286 in KEV

Fortinet's FortiMail has a CVSS 9.8 path traversal flaw under active exploitation. CISA added it to KEV on October 1 with a patch deadline of October 4.

Fortinet FortiMail Zero-Day CVE-2026-104286 in KEV
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

Fortinet confirmed active exploitation of a critical path traversal flaw in FortiMail before a public patch was available. CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities catalog on October 1, 2026. Federal agencies have until October 4 to remediate. Everyone else: the exploitation-in-the-wild confirmation is your deadline.

What the flaw is

CVE-2026-104286 combines a path traversal with improper NULL byte handling in FortiMail. An unauthenticated attacker can send crafted HTTP or HTTPS requests that bypass directory restrictions and write arbitrary files to the underlying system. CVSS score is 9.8 (Critical), per NVD.

BleepingComputer reported that Fortinet warned customers of active exploitation before a public patch was available. That makes this a genuine zero-day: attackers had working access while defenders were still waiting for vendor guidance.

Arbitrary file write on a mail security appliance is not an abstract concern. Attackers with this primitive can drop webshells, manipulate mail processing configs, or stage access deeper into the network segment where FortiMail sits.

Scope

FortiMail, Fortinet’s email security gateway platform. Consult the NVD record and Fortinet’s advisory for the full affected version matrix and fixed releases. Until patched, treat any internet-exposed FortiMail as compromised-adjacent.

What to do

Apply the Fortinet patch. If patching is blocked by a change window, restrict FortiMail management and web interfaces to trusted internal IP ranges and cut external access to the affected endpoints as a bridge measure. Do not leave internet-facing exposure in place and call it mitigated.

After patching, review FortiMail access logs for unexpected activity since at least September 1: newly created files in web-accessible directories, unfamiliar processes, or unusual outbound connections from the appliance.

Federal agencies: CISA BOD 26-04 sets October 4, 2026, as the required remediation date. That window is already closing.

Context

This continues a pattern. In September, CVE-2025-25249 in FortiOS was used in PivotC2 RAT deployment. In August, Fortinet patched CVSS 9.8 flaws in FortiWeb and FortiManager. High-CVSS Fortinet flaws consistently move from advisory to active exploitation on short timelines. If Fortinet gear is in your environment, patch windows need to compress accordingly.

FortiMail specifically handles inbound email traffic and sits at a trusted boundary in many networks. A compromised mail gateway can intercept credentials in transit, redirect mail flows, or serve as a persistent pivot point.

Track all active KEV entries at the 0dayNews KEV tracker.

Related CVEs
  • [ CRITICAL ]CVE-2026-104286Fortinet FortiMail Path Traversal and NULL Byte Flaw

Found this useful? Share it.