Critical FortiMail Zero-Day Under Active Attack: CISA Issues Urgent Warning
CISA has added a critical FortiMail vulnerability, CVE-2026-104286 (CVSS score 9.8), to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw stems from a path traversal issue combined with improper handling of NULL characters, allowing unauthenticated attackers to write arbitrary files on affected systems using specially crafted HTTP or HTTPS requests.
Fortinet has confirmed exploitation in the wild and is urging customers to apply recommended workarounds immediately while patches are prepared for some affected versions. The company credited its own Product Security team with discovering the flaw and has released indicators of compromise to help organisations detect potential breaches. Federal agencies in the US have been told to apply patches or workarounds by October 4, 2026, reflecting the seriousness of the threat.
This disclosure comes amid a wave of active exploitation across multiple vendors, including Check Point, Arista VeloCloud Orchestrator, F5 BIG-IP, Cisco Catalyst SD-WAN Manager, and Citrix NetScaler products, highlighting a broader trend of attackers targeting edge and network infrastructure devices.