Critical FortiMail Zero-Day Exploited in the Wild: CISA Adds CVE-2026-104286 to KEV

Critical FortiMail zero-day CVE-2026-104286 exploited; CISA KEV. Immediate mitigation for email gateways.

  • CVE-2026-104286, a critical unauthenticated path traversal flaw in Fortinet FortiMail, is being actively exploited; CVSS 9.8.
  • No patch is available yet; Fortinet has published a workaround to restrict access and mitigate risk.
  • Affects organizations using FortiMail as an email security gateway; immediate action required.

What to do now

  1. Inventory every FortiMail appliance, including forgotten or lab units, and confirm the installed firmware build.
  2. Apply Fortinet's workaround immediately: restrict management and mail interfaces from the public internet, placing them behind a VPN or IP allowlist.
  3. Hunt for compromise indicators: unexpected files, modified web or config directories, new scheduled tasks, and suspicious outbound connections from the appliance.
  4. Rotate all credentials, API keys, and certificates that touch the device, since unauthenticated access may have exposed them.
  5. Enable full logging to a remote SIEM and monitor for repeat exploitation attempts; report confirmed compromises to CISA and your sector ISAC.

Related items