Fortinet on Thursday warned of a critical path traversal vulnerability in Fortinet FortiMail, which has been exploited in the wild.
The zero-day vulnerability, tracked as CVE-2026-104286, allows an unauthenticated attacker to write arbitrary files on a system through the use of specially crafted HTTP or HTTPS requests.
Fortinet said it has been in touch with government authorities and other stakeholders regarding the threat, and urged customers to apply a workaround. The company did not say when a security patch would be available.
“We are communicating with relevant government organizations, including CISA, on the content of this advisory,” a spokesperson told Cybersecurity Dive.
FortiMail is a platform that provides companies protection from phishing, malware, business email compromise and other potential attacks.
If an attacker can place a file on an underlying system, they can then run commands on the device, according to watchTowr, a firm that tracks security vulnerabilities. This can give an attacker full access to the mail gateway, enabling access to stored mail, credentials and other systems that are connected.
“This is trivial to exploit,” Yordan Ganchev, principal threat intelligence specialist at watchTowr, told Cybersecurity Dive.
The Cybersecurity and Infrastructure Security Agency on Thursday added the flaw to its Known Exploited Vulnerabilities catalog.
Customers should disable identity-based encryption feature support. As an alternative, the FortiMail management interface should be disabled to prevent access from the internet or be limited to trusted private networks.
The company, which did not provide details on when the threat activity began, said the vulnerability was uncovered by one of its researchers.
The zero-day exploitation follows a series of security issues faced by the company over the past year. In June, CISA urged users to secure their Fortinet environments after thousands of firewall and virtual private network credentials were compromised.
Critical vulnerabilities in FortiSandbox were also exploited during that same month.