Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-03 · updated: 2026-10-03 · tags: [incident, global, zero-day] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: true

Fortinet is warning customers that a critical FortiMail vulnerability tracked as CVE-2026-104286, scored 9.8 on CVSS, is being actively exploited in zero-day attacks to execute unauthorised code or commands on vulnerable appliances. A path-traversal and null-byte-neutralisation flaw (CWE-22 / CWE-158) in the FortiMail management interface — specifically its IBE encryption feature — lets an unauthenticated attacker write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. It affects FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9; while 7.2 users can move to the 7.4 branch, no security update yet exists for 7.4, 7.6 or 8.0 installations, with fixed releases listed as upcoming. Until patches land, administrators can disable IBE support or restrict the management interface from the internet. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on the day of disclosure, and Fortinet published indicators of compromise including five added or modified files with SHA-256 hashes.

Attribute Detail
Sector Global (Macro)
Date 2026-10-03
Source The Hacker News
Reliability Tier 2
CVEs CVE-2026-104286