U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
October 02, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog.

The flaw is a path traversal vulnerability that can be triggered through specially crafted HTTP or HTTPS requests. An unauthenticated attacker can exploit the issue to bypass restrictions on file paths and write arbitrary files to the underlying system.

The vulnerability also involves improper handling of NULL characters, which can help the attacker bypass security checks. The flaw is reportedly being exploited in the wild, so affected customers are urged to apply the recommended workaround.

“An Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.” reads the advisory. “This has been reported to be exploited in the wild”

The company did not disclose how many customers were affected, when the attacks started, who was behind them, or technical details of the attacks.

Below are the affected versions and the released updates:

Version Affected Solution
FortiMail 8.0 8.0.0 through 8.0.1 Upgrade to upcoming 8.0.2 or above
FortiMail 7.6 7.6.0 through 7.6.6 Upgrade to upcoming 7.6.7 or above
FortiMail 7.4 7.4.0 through 7.4.8 Upgrade to upcoming 7.4.9 or above
FortiMail 7.2 7.2.0 through 7.2.9 Upgrade to branch 7.4 or above

As a temporary workaround, customers should disable the IBE (Identity-Based Encryption) feature using the recommended CLI command. Alternatively, access to the FortiMail management interface should be blocked from the internet or limited to trusted private networks.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaw by October 3rd, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.