A CVSS 9.8 flaw lets unauthenticated attackers write arbitrary files on Fortinet's email security gateway, and CISA has given federal agencies days to act.
The Hacker News reports that CISA has added CVE-2026-104286, a critical (CVSS 9.8) vulnerability in Fortinet FortiMail, to its Known Exploited Vulnerabilities catalog after attacks in the wild. The bug pairs a path traversal weakness with improper handling of NULL bytes, so a specially crafted HTTP or HTTPS request can let an attacker with no credentials write files anywhere on the appliance.
Fixed builds are available in FortiMail 8.0.2, 7.6.7 and 7.4.9, while customers on the 7.2 branch are told to move to 7.4 or later. Until patching is possible, Fortinet's suggested workarounds are to switch off the Identity-Based Encryption (IBE) feature and keep the management interface away from untrusted networks. Indicators of compromise, including two attacker IP addresses and seven altered or added system files, have been published, and US federal civilian agencies have until October 4, 2026 to remediate.
Why it matters: Email gateways sit at the network edge and see every inbound message, so an unauthenticated file-write flaw is a direct route to persistent access. Patch FortiMail immediately, check appliances against the published indicators of compromise, and treat any internet-exposed management interface as already at risk.