FortiMail Zero-Day Lets Unauthenticated Attackers Write Files to the Mail Gateway and Is Already Exploited (CVE-2026-104286)
Scope: Fortinet FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9
Severity: Red
Fortinet disclosed CVE-2026-104286 (CVSS 9.8), a path traversal flaw combined with improper handling of NULL characters, that lets an unauthenticated attacker write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. Fortinet's own product security team found the issue internally, and the company has confirmed it is being exploited as a zero-day. CISA added it to the Known Exploited Vulnerabilities catalog on October 1 and required federal agencies to carry out forensic triage and mitigate by October 4. Fortinet published workarounds in advisory FG-IR-26-175 for versions that did not yet have a fix, and FortiMail 7.2 users need to upgrade to the 7.4 branch or later. A mail gateway sits in the path of all inbound and outbound email, so an attacker with file-write access on it is well placed to plant code and reach the mail passing through. Organisations running FortiMail must apply the workarounds and install the fixed build for their branch immediately, and should treat any internet-facing FortiMail as potentially compromised until they have reviewed it for unexpected files and unusual web requests.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.