CISA Adds FortiMail Flaw to Exploited Vulnerabilities Catalog
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical vulnerability affecting Fortinet’s FortiMail email security appliances to its Known Exploited Vulnerabilities catalog, citing reports that the flaw is being exploited. The agency’s listing requires federal agencies to address known vulnerabilities, but reports give conflicting dates for the remediation deadline: October 3 and October 4, 2026. The flaw, tracked as CVE-2026-104286 and rated 9.8 on the Common Vulnerability Scoring System, affects FortiMail’s management interface. Fortinet describes it as an unauthenticated path-traversal vulnerability involving improper handling of NULL characters. Crafted HTTP or HTTPS requests may allow an attacker to bypass file-path restrictions and write arbitrary files to the underlying system. Fortinet says the vulnerability is actively exploited. The available information does not establish when the activity began, who is responsible, or how many systems have been compromised. The reports do not provide independent confirmation of the attacks beyond Fortinet’s advisory. Affected versions listed by Fortinet include FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.