CYBERSECURITYTRACKER
TRACKING
Permanent story citation

NCSC-2026-0398 [1.00] [M/H] Vulnerability fixed in Fortinet FortiMail

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 9226

As cited

Copy frozen at (site build).

vulnerabilities

NCSC-2026-0398 [1.00] [M/H] Vulnerability fixed in Fortinet FortiMail

Fortinet released a patch for CVE-2026-104286, a critical vulnerability in FortiMail caused by path traversal and insufficient NULL-byte neutralization that allows unauthenticated attackers to write arbitrary files via crafted HTTP or HTTPS requests. The flaw affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1 with Identity Based Encryption (IBE) enabled, and is being actively exploited in the wild. Fortinet published indicators of compromise to help organizations investigate potential abuse and detect forensic evidence of compromise.

Why it matters: FortiMail administrators running affected versions with IBE enabled face immediate risk of arbitrary file writes by unauthenticated attackers; apply the security update immediately and use the published indicators of compromise to investigate for signs of exploitation.

VendorsFortinet
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

NCSC-2026-0398 [1.00] [M/H] Vulnerability fixed in Fortinet FortiMail

Fortinet released a patch for CVE-2026-104286, a critical vulnerability in FortiMail caused by path traversal and insufficient NULL-byte neutralization that allows unauthenticated attackers to write arbitrary files via crafted HTTP or HTTPS requests. The flaw affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1 with Identity Based Encryption (IBE) enabled, and is being actively exploited in the wild. Fortinet published indicators of compromise to help organizations investigate potential abuse and detect forensic evidence of compromise.

Why it matters: FortiMail administrators running affected versions with IBE enabled face immediate risk of arbitrary file writes by unauthenticated attackers; apply the security update immediately and use the published indicators of compromise to investigate for signs of exploitation.

VendorsFortinet
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary