FORTIMAIL CVE-2026-104286 ZERO-DAY

"FortiMail's 9.8 zero-day is under attack and some versions have no patch yet"

(today) · 3 min read · By Future Technology

Key takeaways

  • CVE-2026-104286 lets an unauthenticated attacker write arbitrary files to a FortiMail appliance
  • It is rated CVSS 9.8 and Fortinet confirms exploitation in the wild
  • Fixed releases for several branches were still listed as upcoming at disclosure
  • CISA gave US federal agencies until 4 October 2026 to patch or apply workarounds

The email gateway is the front door again

Fortinet has confirmed that attackers are exploiting a critical flaw in FortiMail, its secure email gateway, and for several versions there is no fixed release to install yet. The bug is tracked as CVE-2026-104286 and carries a CVSS score of 9.8.

It is a path traversal and null byte handling flaw. In plain terms, a crafted HTTP or HTTPS request to the appliance can trick it into writing files wherever the attacker wants on the underlying system. No login required. Write the right file to the right place and you have code execution on the box that inspects every email your organisation sends and receives.

CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 1 October and told US federal agencies to patch or mitigate by 4 October 2026. That is an unusually short window, and it tells you how seriously CISA rates it.

Affected versions

  • FortiMail 8.0.0 to 8.0.1 (fix: upcoming 8.0.2)
  • FortiMail 7.6.0 to 7.6.6 (fix: upcoming 7.6.7)
  • FortiMail 7.4.0 to 7.4.8 (fix: upcoming 7.4.9)
  • FortiMail 7.2.0 to 7.2.9 (move to 7.4 or later)

Notice the word "upcoming". At disclosure, Fortinet was asking customers to rely on workarounds.

What to do today

Fortinet's guidance is two-fold. First, disable the Identity Based Encryption (IBE) feature from the CLI, using config system encryption ibe, then set status disable, then end. Second, take the FortiMail management interface off the public internet, or restrict it to trusted private networks only.

That second step should already be true for any network appliance. A management interface reachable from the internet is a standing invitation, and this year has made that painfully clear.

Fortinet has also shared indicators of compromise. Check for these files being added: /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice and /data/etc/ld.so.preload. Modified versions of /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz are also red flags, as is traffic from 79.141.169.187 or 45.129.0.192. A new ld.so.preload file is a classic way to make malicious code load into every process, so if you find it, assume full compromise and rebuild.

Part of a much bigger pattern

FortiMail is not alone. In the past few weeks attackers have exploited edge devices from Cisco, Citrix, Check Point, F5 and Arista VeloCloud. We covered the Cisco SD-WAN zero-day earlier this week, and the speed of AI-assisted attacks like JadePuffer's seven-minute Azure wipe shows how little time defenders get once someone is inside.

Edge appliances are attractive because they sit outside most endpoint monitoring, hold credentials, and see sensitive traffic. An email gateway is the best of the lot: it sees password resets, invoices and internal chatter.

If you run FortiMail, treat this as a today job, not a next patch window job. Apply the workarounds now, hunt for the indicators, and install the fixed release the moment it ships.

Sources

    More from Future Technology