Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

https://www.securityweek.com/wp-content/uploads/2025/11/Fortinet-Vulnerability.jpg

The US Cybersecurity and Infrastructure Security Agency (CISA) and Fortinet on Thursday sounded the alarm on a critical FortiMail vulnerability that has been exploited in the wild. Patches have yet to be released.

Tracked as CVE-2026-104286 (CVSS score of 9.8), the zero-day is a path traversal and an improper neutralization of NULL byte or NULL character flaw that could allow attackers to write arbitrary files to the underlying system.

Threat actors could exploit the issue via crafted HTTP or HTTPS requests, potentially gaining arbitrary code or command execution.

Fortinet has published an advisory describing the security defect, urging organizations to disable the IBE feature support or disable access to the FortiMail management interface from the web and limit access to trusted sources.

“This has been reported to be exploited in the wild; customers are urged to apply the workaround,” the company said.

Fortinet also published indicators of compromise (IoCs) to...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE