CISA Flags Exploited FortiMail Zero-Day Requiring Urgent Mitigation

Internet-edge firewalls and VPN gateways monitored in a security operations center

CISA has added CVE-2026-104286, a critical FortiMail vulnerability, to its Known Exploited Vulnerabilities catalog. The October 1 action gives covered organizations an October 4 due date and calls for forensic triage alongside mitigation, reflecting confirmed exploitation rather than a theoretical risk.

Affected FortiMail releases and exposure

Fortinet assigns the flaw a CVSS score of 9.8 and describes it as an unauthenticated path-traversal and null-byte handling issue. According to its advisory, an attacker can use HTTP or HTTPS to write arbitrary files. The affected ranges are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.

Fixed builds were listed as upcoming when the advisory was issued. This creates an immediate operational decision for teams responsible for internet-facing mail infrastructure and the wider cyber-physical security environment: reduce reachable attack surface while also checking systems for evidence of compromise.

Immediate defensive priorities

Fortinet’s stated workaround is to disable IBE or restrict management access to a trusted private network. Administrators should follow the vendor’s current guidance, preserve relevant evidence from mail and management interfaces before making changes, and conduct the forensic triage requested by CISA. Because fixed builds had not yet been listed in the supplied advisory facts, teams should verify the latest vendor notice before making assumptions about patch availability. The watchTowr analysis offers additional technical context, but remediation decisions should remain anchored to current Fortinet and CISA instructions.

Sources and further reading

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *