Content on Harava News is AI-generated and may contain errors. Always verify important information with reliable sources.

Fortinet Warns Attackers Are Actively Exploiting a Critical Zero-Day Vulnerability in FortiMail Appliances

Technology

Fortinet has warned that attackers are actively exploiting a critical, unauthenticated zero-day in FortiMail email-security appliances, allowing them to write arbitrary files and potentially take control of vulnerable systems.

Tracked as CVE-2026-104286, the flaw involves path traversal and improper handling of null characters in FortiMail’s web interface. Attackers can exploit it remotely with specially crafted HTTP or HTTPS requests, without needing an account or password. Fortinet said the vulnerability is being exploited in the wild but has not identified the attackers or disclosed how many customers may have been compromised.

The affected versions include FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9. Fortinet listed fixed releases for versions 8.0.2, 7.6.7 and 7.4.9 as forthcoming, while advising customers on the 7.2 branch to move to version 7.4 or later. Until patches are available, the company recommends disabling Identity-Based Encryption or blocking internet access to the FortiMail management interface and limiting it to trusted private networks.

The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog on October 1, citing evidence of active attacks. Administrators should also review Fortinet’s published indicators of compromise and investigate systems before applying updates or workarounds.