Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet disclosed a critical FortiMail vulnerability, CVE-2026-104286 (CVSS 9.8), in the management interface that lets unauthenticated attackers write arbitrary files via crafted HTTP/HTTPS requests. The flaw is being actively exploited; patches for the 7.4, 7.6 and 8.0 branches are not yet available, and CISA added it to its Known Exploited Vulnerabilities catalog with an October 4 remediation deadline.
- CVE-2026-104286 carries a CVSS score of 9.8 and affects the FortiMail management interface
- Affected versions: 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9
- Fixes 7.4.9, 7.6.7 and 8.0.2 are not yet released; only workarounds are available
- CISA orders US federal agencies to mitigate the flaw by October 4
Read next
Security