CISA has added CVE-2026-104286, a critical FortiMail vulnerability, to its Known Exploited Vulnerabilities catalog. The October 1 action gives covered organizations an October 4 due date and calls for forensic triage alongside mitigation, reflecting confirmed exploitation rather than a theoretical risk.
Affected FortiMail releases and exposure
Fortinet assigns the flaw a CVSS score of 9.8 and describes it as an unauthenticated path-traversal and null-byte handling issue. According to its advisory, an attacker can use HTTP or HTTPS to write arbitrary files. The affected ranges are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.
Fixed builds were listed as upcoming when the advisory was issued. This creates an immediate operational decision for teams responsible for internet-facing mail infrastructure and the wider cyber-physical security environment: reduce reachable attack surface while also checking systems for evidence of compromise.
Immediate defensive priorities
Fortinet’s stated workaround is to disable IBE or restrict management access to a trusted private network. Administrators should follow the vendor’s current guidance, preserve relevant evidence from mail and management interfaces before making changes, and conduct the forensic triage requested by CISA. Because fixed builds had not yet been listed in the supplied advisory facts, teams should verify the latest vendor notice before making assumptions about patch availability. The watchTowr analysis offers additional technical context, but remediation decisions should remain anchored to current Fortinet and CISA instructions.

Leave a Reply