CVE-2026-104286
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail…
CISA federal remediation date Oct 4
Vulnerabilities · 18h ago
Fortinet says CVE-2026-104286 is already being actively exploited in FortiMail, its email gateway product, across multiple 7.x and 8.x releases. CISA has also put the flaw on its Known Exploited Vulnerabilities list, with federal remediation due in two days.
The bug is an unauthenticated path traversal: a request to the public mail service can make FortiMail reach outside the folder boundary it should stay within, so an attacker does not need a password to start the compromise. In plain terms, the gateway can be tricked into opening or touching data it should never see.
That puts the exposure on any internet-facing FortiMail appliance, not on a logged-in admin console. For teams that treated the box as a filter sitting at the edge, the blast radius is the gateway itself, and the reporting does not yet show which attacks or victims are tied to this campaign.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail…
CISA federal remediation date Oct 4
1 source covering this story
Fortinet sounds the alarm over actively exploited FortiMail zero-day
No login required, exploitation underway, and some admins are still waiting for patches
Part of the PlainSec briefing for 2026-10-03