Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

Summary

A critical-severity path traversal vulnerability, identified as CVE-2026-104286, has been discovered in Fortinet FortiMail. This vulnerability allows attackers to write arbitrary files to the system, and active exploitation has been noted, necessitating urgent action from users.

IFF Assessment

FOE

The active exploitation of a critical vulnerability presents a direct threat to systems and data, making it bad news for defenders.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: October 04, 2026. Known ransomware use: Unknown.

Defender Context

Defenders must prioritize patching or mitigating systems affected by this FortiMail zero-day vulnerability to prevent unauthorized file writes and potential system compromise. Organizations should review their security logs for any signs of exploitation and implement strict access controls and network segmentation as a defense-in-depth measure.

Read Full Story →