Overview
- Fortinet confirmed on Oct. 1–2 that CVE-2026-104286 is being actively exploited in the wild and urged customers to follow its advisory.
- The flaw is a path‑traversal plus NULL‑byte handling bug in the FortiMail management interface that can let an unauthenticated attacker write arbitrary files and enable command or code execution.
- Fortinet published indicators of compromise including file hashes, added or modified system files, two attacker IP addresses, and example log entries to help detection and hunting.
- Full security updates are listed but not yet released for several FortiMail branches, so Fortinet recommends disabling IBE and blocking internet access to management interfaces as temporary workarounds.
- CISA added the CVE to its Known Exploited Vulnerabilities catalog and ordered federal mitigation and forensic triage by October 4, and organizations are advised to inventory FortiMail instances, rotate credentials, and perform forensic checks because patches alone may not remove active backdoors.