Critical FortiMail Flaw Threatens Enterprise Email Gateways

Fortinet has warned that CVE-2026-104286, a critical FortiMail path traversal vulnerability, is being actively exploited. The CVSS 9.8 flaw allows unauthenticated attackers to write arbitrary files through crafted web requests, potentially enabling persistent access and control of the email security appliance. Published indicators suggest attackers may be modifying Linux preload settings, adding malicious libraries, and altering web server configurations. Organizations should patch immediately, restrict public access to management interfaces, apply Fortinet’s workaround, and investigate affected devices.

Reference: scworld.com