Fortinet warns of exploited FortiMail flaw with no fixed release out
Attackers are already using the critical bug to write files to email gateways. Until fixed releases arrive, mid-market firms depend on a workaround and on whoever runs their kit
- Affected: FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9
- Fortinet lists 8.0.2, 7.6.7 and 7.4.9 as upcoming fixed releases
- The 7.2 branch gets no fix; its users must move to 7.4 or above
- Advisory FG-IR-26-175 rates the flaw 9.8 on CVSS v3, found by Fortinet's own product security team
Directors should get written confirmation from their IT provider or MSP of whether the firm runs FortiMail, on which version and whether the workaround is in place today rather than at the next maintenance window. Ask for the gateway's logs and archive settings to be checked against Fortinet's published indicators and for the upgrade to be booked for the day fixed builds ship. Firms on the oldest affected branch should plan a version migration rather than wait for a patch.
“This has been reported to be exploited in the wild, customers are urged to apply the workaround below.”Fortinet, security advisory FG-IR-26-175
Fortinet disclosed on 1 October that attackers are exploiting a critical flaw in FortiMail, its email security gateway. The bug, CVE-2026-104286, lets an unauthenticated attacker write arbitrary files to the appliance through crafted HTTP or HTTPS requests, and Fortinet lists the impact as the execution of unauthorized code or commands.
The weakness pairs a path-traversal error with poor handling of null bytes, and it sits in the web-facing side of FortiMail's identity-based encryption (IBE) feature. With no fixed builds shipped for any affected branch, Fortinet's advice rests on a workaround: switch the IBE service off, or stop the webmail interface being reached from the internet and allow it only from trusted private networks. Firms with a web application firewall in front of the gateway can block the malicious request pattern there instead.
The advisory also lists two attacker IP addresses and sample log entries. One shows a new archive account being added and pointed at a remote server at one of those addresses – the kind of change that could see archived email copied off the gateway.
For UK small and medium-sized businesses and mid-market firms whose Fortinet equipment is run by an outsourced IT provider or managed service provider (MSP), the response sits in someone else's hands. That makes the question for a board one of evidence, not assurance.
Sources
- Fortinet, “Improper Limitation of a Pathname to a Restricted Directory”, PSIRT advisory FG-IR-26-175, 1 October 2026. https://fortiguard.fortinet.com/psirt/FG-IR-26-175
- CVE Program, CVE-2026-104286 record, 1 October 2026. https://cveawg.mitre.org/api/cve/CVE-2026-104286
- Help Net Security, “Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)”, 2 October 2026. https://www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-104286/
