Vulnerabilities & Exploits · Zero-Day Exploit

FortiMail Exploitation Hits Internet-Facing Gateways

Fortinet says CVE-2026-104286 is already being actively exploited in FortiMail, its email gateway product, across multiple 7.x and 8.x releases. CISA has also put the flaw on its Known Exploited Vulnerabilities list, with federal remediation due in two days.

The bug is an unauthenticated path traversal: a request to the public mail service can make FortiMail reach outside the folder boundary it should stay within, so an attacker does not need a password to start the compromise. In plain terms, the gateway can be tricked into opening or touching data it should never see.

That puts the exposure on any internet-facing FortiMail appliance, not on a logged-in admin console. For teams that treated the box as a filter sitting at the edge, the blast radius is the gateway itself, and the reporting does not yet show which attacks or victims are tied to this campaign.

1 source · 20h ago

CVE-2026-104286

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail…

CISA federal remediation date Oct 4

Timeline

Sources

Vendor digest: Fortinet

Part of the PlainSec briefing for 2026-10-03

Every edition of this story: FortiMail Exploitation Hits Internet-Facing Gateways

More from today