Fortinet FortiMail Path Traversal Vulnerability (CVE-2026-104286) is being actively exploited, CISA warns
CISA added CVE-2026-104286 (Fortinet FortiMail) to its Known Exploited Vulnerabilities catalog on October 1, 2026, which means there is reliable evidence of exploitation in the wild. Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or…
CISA lists this as exploited in the wild. Unpatched FortiGate / FortiOS and FortiMail systems are exposed to active attacks now.
Treat this as an emergency.
