U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog.
The flaw is a path traversal vulnerability that can be triggered through specially crafted HTTP or HTTPS requests. An unauthenticated attacker can exploit the issue to bypass restrictions on file paths and write arbitrary files to the underlying system.
The vulnerability also involves improper handling of NULL characters, which can help the attacker bypass security checks. The flaw is reportedly being exploited in the wild, so affected customers are urged to apply the recommended workaround.
“An Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.” reads the advisory. “This has been reported to be exploited in the wild”
The company did not disclose how many customers were affected, when the attacks started, who was behind them, or technical details of the attacks.
Below are the affected versions and the released updates:
| Version | Affected | Solution |
|---|---|---|
| FortiMail 8.0 | 8.0.0 through 8.0.1 | Upgrade to upcoming 8.0.2 or above |
| FortiMail 7.6 | 7.6.0 through 7.6.6 | Upgrade to upcoming 7.6.7 or above |
| FortiMail 7.4 | 7.4.0 through 7.4.8 | Upgrade to upcoming 7.4.9 or above |
| FortiMail 7.2 | 7.2.0 through 7.2.9 | Upgrade to branch 7.4 or above |
As a temporary workaround, customers should disable the IBE (Identity-Based Encryption) feature using the recommended CLI command. Alternatively, access to the FortiMail management interface should be blocked from the internet or limited to trusted private networks.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaw by October 3rd, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
