Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
Summary
A critical-severity path traversal vulnerability, identified as CVE-2026-104286, has been discovered in Fortinet FortiMail. This vulnerability allows attackers to write arbitrary files to the system, and active exploitation has been noted, necessitating urgent action from users.
IFF Assessment
The active exploitation of a critical vulnerability presents a direct threat to systems and data, making it bad news for defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: October 04, 2026. Known ransomware use: Unknown.
Defender Context
Defenders must prioritize patching or mitigating systems affected by this FortiMail zero-day vulnerability to prevent unauthorized file writes and potential system compromise. Organizations should review their security logs for any signs of exploitation and implement strict access controls and network segmentation as a defense-in-depth measure.