Download Privacy Needle App

Type to search

Cybersecurity

Fortinet FortiMail Zero-Day Actively Exploited, Urgent Action Needed

Share

A critical zero-day vulnerability in Fortinet’s FortiMail email security appliance, tracked as CVE-2026-104286, is being actively exploited in the wild, prompting urgent warnings from the US Cybersecurity and Infrastructure Security Agency (CISA) and Fortinet itself.

The flaw, which carries a maximum CVSS score of 9.8 (Critical), is a path traversal and improper neutralisation of NULL byte or NULL character vulnerability. It could allow attackers to write arbitrary files to the underlying system via crafted HTTP or HTTPS requests, potentially leading to remote code or command execution (RCE).

Urgent Mitigation and Patch Plans

Fortinet discovered the security defect internally and has released an advisory urging customers to implement immediate workarounds. These include disabling the IBE (Identity Based Encryption) feature support or restricting access to the FortiMail management interface from the web, limiting it only to trusted sources.

The company has also published indicators of compromise (IoCs) to assist security teams in detecting potential intrusions.

CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies address the issue within three days, in line with Binding Operational Directive (BOD) 26-04.

Affected versions of FortiMail include 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1.

Despite the active exploitation, patches have yet to be released. Fortinet has stated that fixes will be included in upcoming FortiMail versions 7.4.9, 7.6.7, and 8.0.2, but has not provided a specific release timeline. Neither Fortinet nor CISA has publicly disclosed details regarding the nature or scope of the observed attacks.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.