Skip to main content

Software

Fortinet warns of critical FortiMail zero-day exploited in attacks

Fortinet disclosed CVE-2026-104286, a critical FortiMail flaw scoring 9.8, exploited in attacks, with US federal agencies required to mitigate it by October 4, 2026.

Fortinet warns of critical FortiMail zero-day exploited in attacksPhoto: BleepingComputer

Key points

Fortinet disclosed CVE-2026-104286, a critical FortiMail flaw scoring 9.8 that attackers are actively exploiting to write arbitrary files on vulnerable systems.

Fortinet warned customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that attackers are actively exploiting in zero-day attacks to execute unauthorized code or commands on vulnerable devices. The flaw scores 9.8 on the Common Vulnerability Scoring System and affects the FortiMail management interface, the company said in an advisory published on October 1, 2026.

The vulnerability matters because it lets an unauthenticated attacker — someone with no account or credentials — write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. Fortinet rated it critical, and the US Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalog the same day, requiring federal civilian agencies to act by October 4, 2026.

What the flaw allows

Fortinet's advisory attributes the flaw to two weaknesses: improper limitation of a pathname to a restricted directory, known as path traversal (CWE-22), and improper neutralisation of a NULL byte or NULL character (CWE-158). Together, these let crafted requests escape the intended directory and place attacker-chosen files anywhere on the appliance's file system.

Gwendal Guégniaud of Fortinet's Product Security team discovered the vulnerability internally, according to the advisory. Fortinet said the flaw is being actively exploited and urged customers to apply shared workarounds until a security update can be installed. The company has not said when the flaw was first exploited, how many systems were compromised, or who is behind the attacks.

The flaw affects four release branches: FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet lists FortiMail 7.4.9, 7.6.7 and 8.0.2 as upcoming versions containing the fix, but those updates have not been released. FortiMail 7.2 users can patch by upgrading to the 7.4 branch or later.

Which versions are affected

Until patched versions ship, Fortinet advises administrators to disable IBE — identity-based encryption, a feature that encrypts messages per recipient — using the commands `config system encryption ibe`, `set status disable`, `end`. As an alternative, admins can block internet access to the FortiMail management interface or restrict it to trusted private networks.

What remains unconfirmed

Fortinet has not disclosed when the flaw was first exploited, how many systems were compromised, or who is behind the attacks. The company said it is communicating with relevant government organisations, including CISA, on the advisory's content. CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4, 2026. Administrators waiting on FortiMail 7.4.9, 7.6.7 and 8.0.2 can check their appliances against the published file hashes, IP addresses and log entries. The next dated deadline falls on October 4, 2026, when US federal civilian agencies must complete forensic triage and mitigation of CVE-2026-104286.

Frequently asked questions

What is CVE-2026-104286?

CVE-2026-104286 is a critical FortiMail vulnerability scoring 9.8 that combines path traversal (CWE-22) and NULL byte neutralisation issues (CWE-158), letting an unauthenticated attacker write arbitrary files via crafted HTTP or HTTPS requests.

Which FortiMail versions are affected?

FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fixes are upcoming in 7.4.9, 7.6.7 and 8.0.2; 7.2 users can upgrade to the 7.4 branch.

How can administrators mitigate the flaw now?

Disable IBE support via `config system encryption ibe`, `set status disable`, `end`, or block internet access to the FortiMail management interface and restrict it to trusted private networks until patched versions ship.

How this story was checked

  • Fact-checked against 3 cited pages. 66 figures, dates and quotations in this story were found on the pages it cites; 2 passages that could not be checked were cut before publication.
  • Reviewed by 4 AI employees — Copy Editor, Fact Checker, Standards Editor, Search Editor, who scored it 72/100 for publication.
Pages checked (3 of 3)
  • bleepingcomputer.comread and checked
  • thehackernews.comread and checked
  • helpnetsecurity.comread and checked

Written by Kaer from public reporting. Checked 2 October 2026.

3 sources

More from this edition