Fortinet is warning customers about a critical FortiMail zero-day flaw that lets unauthenticated attackers write arbitrary files to vulnerable systems. The vulnerability, tracked as CVE-2026-104286, carries a CVSS score of 9.8. CISA has added it to its Known Exploited Vulnerabilities catalog after confirming active exploitation.
FortiMail sits at the edge of the mail flow, inspecting inbound and outbound messages for spam, phishing and malware, which usually means its management interface is reachable from outside the network it protects. An attacker who can write files to that interface is one step from running code on a system with visibility into every message crossing the gateway, which is what makes this flaw worth treating as urgent rather than routine patch-cycle work.
How the FortiMail zero-day flaw bypasses authentication
Fortinet describes the bug as a combination of path traversal and improper handling of null characters in FortiMail’s web interface. Path traversal lets a request escape the directory a web application expects to write into, climbing back up the filesystem with sequences like ../. Pairing that with null-character handling is an older trick: file-handling code can treat a null byte as a string terminator, letting an attacker smuggle a different path or extension past a check that only read the string up to that point.
Combined, the two issues give an attacker enough control to place a file exactly where they want it on the appliance, using nothing more than a specially crafted HTTP or HTTPS request and no credentials at all. Writing to the right location is enough to execute code or commands, which is what turns a file-write bug into full device compromise.
The flaw affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. That spread covers every maintained branch of the product, so version-pinning isn’t a workaround: anyone running FortiMail needs to check their build number against Fortinet’s advisory directly rather than assume an older release is safe.
What CISA’s KEV listing adds, and what’s still missing
CISA’s Known Exploited Vulnerabilities catalog is reserved for flaws with confirmed real-world exploitation, and CVE-2026-104286 was added to it this week. Fortinet’s own advisory states that the vulnerability “is being exploited in the wild,” but stops there: it gives no date for when the attacks started, no attribution, and no count of how many customers have been hit, as The Register noted. For admins deciding how urgently to patch, that gap matters: a flaw exploited by one opportunistic actor against a handful of targets calls for a different response than one already being used at scale.
Another appliance zero-day joins a crowded list
FortiMail joins a run of perimeter and email security appliances that have taken the same path this year: a vendor advisory followed within days by a CISA KEV listing. Citrix confirmed two NetScaler zero-days under active attack earlier this year, and the pattern repeats: an internet-facing management interface, unauthenticated exploitation, and a scramble to patch before a public proof-of-concept arrives.
If a FortiMail instance exposes its web interface to anything beyond a restricted management network, that exposure is the thing to close this week, not just the software version. Patching clears the specific bug; it does nothing about the next one if the interface is still sitting on the open internet.








