Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)

Oct 02, 2026 - 11:15
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)

Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available. About CVE-2026-104286 “An Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker … More →

The post Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) appeared first on Help Net Security.