The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security vulnerability affecting Fortinet FortiMail products to its Known Exploited Vulnerabilities (KEV) catalog after confirming reports of active exploitation. The flaw, tracked as CVE-2026-104286 with a CVSS severity score of 9.8, could allow unauthenticated attackers to write arbitrary files on affected systems, creating potential risks for organizations relying on FortiMail for secure email infrastructure.
According to Fortinet’s security advisory, the vulnerability is linked to improper pathname restriction and improper handling of NULL characters. The security issue, classified under path traversal and NULL byte vulnerabilities, may allow attackers without authentication to write arbitrary files on the underlying system by sending specially crafted HTTP or HTTPS requests. Fortinet has acknowledged that the vulnerability has been exploited in real world attacks and has advised customers to apply available fixes or follow recommended mitigation steps until updates are deployed. The affected versions include FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8 and FortiMail 7.2.0 through 7.2.9. Customers using these versions are advised to upgrade to the relevant patched releases once available. Fortinet has also recommended temporary security measures for certain deployments, including disabling IBE feature support through the FortiMail command line interface and restricting access to the FortiMail management interface from the public internet. Organizations are encouraged to limit administrative access to trusted private networks where possible.
Fortinet credited Gwendal Guégniaud from the Fortinet Product Security team for identifying and reporting the vulnerability. The company has also shared indicators of compromise associated with observed exploitation activity, including specific IP addresses and file changes that security teams can use for detection and investigation. The identified indicators include IP addresses such as 79.141.169[.]187 and 45.129.0[.]192, along with files including /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz. Due to ongoing exploitation activity, Federal Civilian Executive Branch (FCEB) agencies have been advised to apply available patches or implement recommended workarounds by October 4, 2026. Security teams across other sectors are also encouraged to review their FortiMail deployments, monitor systems for suspicious activity and prioritize remediation efforts based on their exposure.
The FortiMail vulnerability is part of a wider trend involving enterprise security products being targeted through newly discovered flaws. Recent months have seen multiple vulnerabilities affecting widely used networking and security platforms, including products from Check Point, Arista VeloCloud Orchestrator, F5 BIG-IP Access Policy Manager, Cisco Catalyst SD-WAN Manager and Citrix NetScaler ADC and NetScaler Gateway. Several of these vulnerabilities have also been reported as exploited in active attacks, highlighting the importance of timely patching, continuous monitoring and stronger vulnerability management practices across enterprise environments.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





