Fortinet is warning that a critical zero-day vulnerability in its FortiMail email security gateway, tracked as CVE-2026-104286, is being exploited in the wild. Multiple outlets report that the issue involves path traversal and related input handling problems, and that attackers can compromise vulnerable systems without authentication. The Hacker News adds that CISA has added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, indicating it is actively targeted.
Outlets describe the practical impact as enabling unauthorized actions on affected FortiMail devices, including arbitrary file writes on the underlying system. Reported severity is high, with SecurityWeek citing critical risk and noting that exploitation could allow attackers to write arbitrary files. Help Net Security and Bleeping Computer focus on Fortinet’s customer guidance, including applying a workaround provided by the vendor while awaiting full fixes. Across reports, the emphasis differs: some stress the technical risk of arbitrary file access, while others stress urgent mitigation steps.
All sources converge on the same core message: CVE-2026-104286 is currently exploited, and Fortinet’s recommended workaround is the immediate action for customers until patched remediation is available.