Fortinet is urging customers to apply workarounds for an actively exploited zero-day in its FortiMail secure email gateway while fixes remain in the pipeline. CISA added the flaw, tracked as CVE-2026-104286, to its Known Exploited Vulnerabilities catalog on October 1 and set a three-day deadline for federal civilian agencies.
The bug carries a CVSS score of 9.8. Fortinet describes a path traversal flaw (CWE-22) combined with improper handling of a NULL byte (CWE-158) that lets an unauthenticated attacker write arbitrary files to the underlying system through crafted HTTP or HTTPS requests, opening the door to code execution. FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6 and 8.0.0 through 8.0.1 are affected; fixes are slated for 7.4.9, 7.6.7 and 8.0.2 with no release date announced.
Until then, Fortinet says to disable the Identity-Based Encryption feature or cut the management interface off from the internet and restrict it to trusted networks. The company also published indicators of compromise.
Healthcare providers lean on secure email gateways to filter phishing, still a leading way intruders get inside hospital networks. An unauthenticated file-write flaw on that gateway is a serious foothold, so health systems running FortiMail should treat the workaround as urgent and check the vendor’s compromise indicators.