Skip to content
Updated Oct 5, 2026 · 09:37 UTCSearchRSS
The ICT Trends

Telecom, cloud, AI and enterprise technology news

Fortinet warns of FortiMail zero-day under attack, with some patches still pending

A critical FortiMail flaw, CVE-2026-104286, lets unauthenticated attackers write files to appliances. Fixes for several branches are not yet out.

The ICT Trends Newsdesk1 min read

Fortinet has told customers to lock down its FortiMail email security platform after confirming that attackers are exploiting a critical vulnerability that requires no login.

The flaw, CVE-2026-104286, has a CVSS score of 9.8. Fortinet's advisory describes it as a path traversal weakness combined with improper handling of null characters in the product's web interface. By sending crafted HTTP or HTTPS requests, an unauthenticated attacker can write arbitrary files to the underlying system, which The Register notes could lead to code or command execution depending on where the files land.

Affected releases are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9. According to The Hacker News, the fixed versions for the 8.0, 7.6 and 7.4 branches are listed as upcoming, and 7.2 users are told to move to 7.4 or later.

Workarounds while fixes arrive

Until updates are available, Fortinet recommends turning off Identity Based Encryption where it is not needed. Customers who cannot do that should make sure the FortiMail management interface is not reachable from the internet and limit access to trusted private networks.

The advisory confirms exploitation in the wild but does not say when it started, who is responsible or how many customers were affected, The Register reports. Fortinet has published indicators of compromise, including suspicious files, configuration changes and IP addresses linked to the attacks. Administrators are advised to check for them, since a workaround will not remove anything an attacker has already planted.

CISA has added the flaw to its Known Exploited Vulnerabilities catalog and directed US federal civilian agencies to act by October 4. Fortinet credited Gwendal Guégniaud of its own product security team with finding the bug.