Critical FortiMail Zero-Day Exploited in the Wild: CISA Adds CVE-2026-104286 to KEV
Critical FortiMail zero-day CVE-2026-104286 exploited; CISA KEV. Immediate mitigation for email gateways.
- CVE-2026-104286, a critical unauthenticated path traversal flaw in Fortinet FortiMail, is being actively exploited; CVSS 9.8.
- No patch is available yet; Fortinet has published a workaround to restrict access and mitigate risk.
- Affects organizations using FortiMail as an email security gateway; immediate action required.
What to do now
- Inventory every FortiMail appliance, including forgotten or lab units, and confirm the installed firmware build.
- Apply Fortinet's workaround immediately: restrict management and mail interfaces from the public internet, placing them behind a VPN or IP allowlist.
- Hunt for compromise indicators: unexpected files, modified web or config directories, new scheduled tasks, and suspicious outbound connections from the appliance.
- Rotate all credentials, API keys, and certificates that touch the device, since unauthenticated access may have exposed them.
- Enable full logging to a remote SIEM and monitor for repeat exploitation attempts; report confirmed compromises to CISA and your sector ISAC.
Related items
- Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
- U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
- Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
- Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
- Fortinet sounds the alarm over actively exploited FortiMail zero-day
- Kiteworks Citrix Incidents Show Challenges of Zero-Day Response
- Warlock ransomware breach SharePoint in water, telecom operator attacks