Security researchers said that attackers can gain access to credentials, stored mail and other connected systems.
Courtesy of Fortinet
Fortinet on Thursdaywarned of a critical path traversal vulnerabilityin Fortinet FortiMail, which has been exploited in the wild.
The zero-day vulnerability, tracked asCVE-2026-104286, allows an unauthenticated attacker to write arbitrary files on a system through the use of specially crafted HTTP or HTTPS requests.
Fortinet said it has been in touch with government authorities and other stakeholders regarding the threat, and urged customers to apply a workaround. The company did not say when a security patch would be available.
“We are communicating with relevant government organizations, including CISA, on the content of this advisory,” a spokesperson told Cybersecurity Dive.
FortiMail is a platform that provides companies protection from phishing, malware, business email compromise and other potential attacks.
If an attacker can place a file on an underlying system, they can then run commands on the device,<a href="https://watchtowr.com/intelligence/fortinet-fortimail-cve-2026-104286-faq/#elementor-toc__heading-anchor-0″ rel=”nofollow noopener” target=”_blank”>according to watchTowr, a firm that tracks security vulnerabilities. This can give an attacker full access to the mail gateway, enabling access to stored mail, credentials and other systems that are connected.
“This is trivial to exploit,” Yordan Ganchev, principal threat intelligence specialist at watchTowr, told Cybersecurity Dive.
TheCybersecurity and Infrastructure Security Agencyon Thursday added the flaw to its Known Exploited Vulnerabilities catalog.
Customers should disable identity-based encryption feature support. As an alternative, the FortiMail management interface should be disabled to prevent access from the internet or be limited to trusted private networks.
The company, which did not provide details on when the threat activity began, said the vulnerability was uncovered by one of its researchers.
The zero-day exploitation follows a series of security issues faced by the company over the past year. In June, CISAurged usersto secure their Fortinet environments after thousands of firewall and virtual private network credentials were compromised.
Criticalvulnerabilities in FortiSandboxwere also exploited during that same month.
