MikhbarMIKHBAR
Cybersecurity

Fortinet Warns of Exploited FortiMail Zero-Day

Fortinet and the US Cybersecurity and Infrastructure Security Agency (CISA) have issued urgent warnings regarding a critical zero-day vulnerability in FortiMail that is currently being exploited in the wild.

Fortinet Warns of Exploited FortiMail Zero-Day

Urgent Security Alert Issued

The US Cybersecurity and Infrastructure Security Agency (CISA) and Fortinet on Thursday sounded the alarm on a critical FortiMail vulnerability that has been exploited in the wild. Patches have yet to be released, leaving organizations to rely on immediate workarounds to mitigate the risk. The joint warning highlights the severity of the threat, which has been actively targeted by threat actors despite the lack of a public fix.

Technical Details of the Flaw

Tracked as CVE-2026-104286, the zero-day carries a CVSS score of 9.8, indicating a critical severity level. The vulnerability is characterized as a path traversal and an improper neutralization of NULL byte or NULL character flaw. This combination allows attackers to write arbitrary files to the underlying system. Threat actors could exploit the issue via crafted HTTP or HTTPS requests, potentially gaining arbitrary code or command execution on the affected servers.

Recommended Mitigation Steps

Fortinet has published an advisory describing the security defect, urging organizations to disable the IBE feature support or disable access to the FortiMail management interface from the web and limit access to trusted sources. The company emphasized the immediate need for these measures, stating, “This has been reported to be exploited in the wild; customers are urged to apply the workaround.” Additionally, Fortinet published indicators of compromise (IoCs) to help security teams hunt for potential intrusions within their networks.

CISA Adds Bug to KEV Catalog

On Thursday, CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog. This addition mandates federal agencies to address the vulnerability within three days, as required by Binding Operational Directive 26-04. The inclusion in the KEV catalog signals that the vulnerability is being actively exploited in the wild and poses a significant risk to government infrastructure and other critical sectors.

Affected Versions and Patch Timeline

According to Fortinet, the security bug was discovered internally and affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1. The company states that fixes will be included in the upcoming FortiMail versions 7.4.9, 7.6.7, and 8.0.2. However, Fortinet has not provided a specific release timeline for these updates, leaving administrators to manage the risk through the recommended workarounds in the interim.

Lack of Attack Details

Neither Fortinet nor CISA has provided specific details on the observed attacks, such as the identity of the threat actors or the specific targets involved. This lack of transparency is common in zero-day disclosures where the primary goal is to prompt immediate remediation without providing a blueprint for further exploitation. Security teams are advised to monitor their logs for the provided indicators of compromise to determine if their systems have been compromised.

Context of Recent Zero-Days

This incident follows a series of recent zero-day vulnerabilities affecting other enterprise software. For instance, a Zimbra vulnerability was exploited in the wild prior to public disclosure, and Zammad zero-days were exploited in an AI-powered DIVD hack. Additionally, Cisco recently patched an exploited Catalyst SD-WAN zero-day vulnerability, and government and finance organizations were targeted in weeks-long NetScaler zero-day attacks. These events underscore the persistent threat landscape facing organizations that rely on complex network and email infrastructure.

Sources

  • SecurityWeekExploited Fortinet FortiMail Zero-Day Calls for Urgent Action

Continue chronologically

You are readingFortinet Warns of Exploited FortiMail Zero-Day
Fortinet warns of critical FortiMail zero-day flaw
Older storyFortinet warns of critical FortiMail zero-day flawOctober 2, 2026 · 4 min