Product

FortiMail

Made by Fortinet. 1 of its vulnerabilities are known to have been exploited.

Coverage

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Fortinet FortiMail Path Traversal Vulnerability (CVE-2026-104286) is being actively exploited, CISA warns

CISA added CVE-2026-104286 (Fortinet FortiMail) to its Known Exploited Vulnerabilities catalog on October 1, 2026, which means there is reliable evidence of exploitation in the wild. Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or…

Why it matters

CISA lists this as exploited in the wild. Unpatched FortiGate / FortiOS and FortiMail systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Recent intelligence

The latest developments from the last 30 days, newest first.

  1. Severity raisedUpdateKEV

    UPDATE: severity raised to critical: Fortinet FortiMail Path Traversal Vulnerability (CVE-2026-104286) is being actively exploited, CISA warns

    Basis: CISA Known Exploited Vulnerabilities (government advisory)

  2. AdvisoryKEV

    Fortinet FortiMail Path Traversal Vulnerability (CVE-2026-104286) is being actively exploited, CISA warns

    Basis: CISA Known Exploited Vulnerabilities (government advisory)

  3. Added to CISA KEVCVE-2026-104286

    CVE-2026-104286 added to CISA KEV: Fortinet FortiMail, Fortinet FortiMail Path Traversal Vulnerability

    Basis: CISA Known Exploited Vulnerabilities catalog

Actively exploited