FortiMail CVE-2026-104286: Critical Zero-Day Exploited, Patch Now
A critical, unauthenticated path-traversal flaw in FortiMail is under active attack. CISA added it to its exploited-vulnerabilities list the same day Fortinet disclosed it.

Fortinet has confirmed that a critical, unauthenticated vulnerability in FortiMail, tracked as CVE-2026-104286, is being actively exploited in the wild. The flaw, rated 9.8 out of 10 on the CVSS scale, lets an attacker with no credentials write arbitrary files to a vulnerable FortiMail appliance using nothing more than a crafted web request — a technique that can lead to full remote code execution. Fortinet disclosed the flaw on October 1, 2026, the same day the Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog and gave U.S. federal civilian agencies until October 4 to patch or disconnect affected systems; fixed versions followed in an advisory update on October 5.
What happened: Fortinet disclosed CVE-2026-104286, a critical path-traversal flaw in FortiMail, on October 1, 2026, confirming it has already been exploited in the wild.
What's affected: FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1, specifically systems with internet-reachable webmail or management interfaces.
What to do: Upgrade to FortiMail 7.4.9, 7.6.7, or 8.0.2 (or branch 7.4+ if you're on 7.2). If you can't patch immediately, disable the IBE feature and block internet access to the management interface now.
What happened with FortiMail CVE-2026-104286
On October 1, 2026, Fortinet's Product Security Incident Response Team (PSIRT) published advisory FG-IR-26-175, disclosing a critical vulnerability in FortiMail, the company's email security gateway appliance. The advisory was unusual in that it arrived with an active-exploitation notice already attached: Fortinet said it had evidence the flaw was "reported as exploited in the wild" at the time of disclosure, meaning attackers were using it against real FortiMail deployments before a patch was even available for most affected branches.
The vulnerability was identified internally by Gwendal Guégniaud of Fortinet's own Product Security team. Fortinet has not published a detailed account of who is behind the observed attacks or how many organizations have been targeted, but its advisory lists specific indicators — including file paths and network addresses tied to the intrusions — that administrators can use to check their own systems for compromise.
CISA moved immediately, adding CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on the same day it was disclosed. Under Binding Operational Directive 26-04, that action gave federal civilian executive branch agencies until October 4, 2026 — just three days — to apply Fortinet's mitigations, follow CISA's forensic triage guidance, or take the affected product offline entirely. The compressed timeline reflects how CISA treats pre-authentication, remotely exploitable flaws in internet-facing security appliances: the same urgency it applied to the Citrix NetScaler zero-day disclosed weeks earlier.
What CVE-2026-104286 actually is
According to Fortinet's advisory, CVE-2026-104286 combines two separate weaknesses: an Improper Limitation of a Pathname to a Restricted Directory, commonly known as path traversal (CWE-22), and an Improper Neutralization of NULL Byte or NULL Character flaw (CWE-158). Chained together, they let an attacker send a specially crafted HTTP or HTTPS request to a FortiMail system and write files to locations on the underlying operating system that should be off-limits — without supplying any username, password, or authentication token.
Writing arbitrary files to an appliance's filesystem is rarely the end goal on its own. In practice, flaws like this are typically used to drop a web shell, modify a legitimate system file, or plant a scheduled task that gives the attacker a persistent foothold and a path to execute their own code with the privileges of the FortiMail service. That's reflected in the vulnerability's CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), which rates the flaw as network-exploitable, low-complexity, requiring no privileges and no user interaction, with high impact to confidentiality, integrity, and availability — the profile of a vulnerability capable of producing full system compromise.
Fortinet's advisory and subsequent reporting point to FortiMail's identity-based encryption (IBE) component and its webmail interface as the exposed attack surface. Any organization that exposes FortiMail's management interface or webmail portal directly to the internet — rather than restricting it to a VPN or internal network — is directly exposed to pre-authentication exploitation.
Which FortiMail versions are affected
The vulnerability spans four FortiMail release branches. Fortinet's advisory, last updated October 5, 2026, lists the following vulnerable ranges and fixed releases:
| FortiMail branch | Vulnerable versions | Fixed version |
|---|---|---|
| 8.0 | 8.0.0 – 8.0.1 | 8.0.2 or later |
| 7.6 | 7.6.0 – 7.6.6 | 7.6.7 or later |
| 7.4 | 7.4.0 – 7.4.8 | 7.4.9 or later |
| 7.2 | 7.2.0 – 7.2.9 | Upgrade to 7.4 or later (no 7.2 fix) |
Notably, Fortinet is not releasing a patched build on the 7.2 branch at all; organizations still running 7.2.x are instructed to upgrade to 7.4.9 or later rather than wait for a point fix. Earlier, unsupported FortiMail branches are not addressed in the advisory, which generally means they should be treated as vulnerable and unsupported going forward.
Is CVE-2026-104286 being actively exploited right now
Yes. Fortinet's own advisory states the flaw has been observed exploited in the wild, and CISA's decision to add it to the KEV catalog on the day of disclosure — rather than after a period of monitoring — reflects that same assessment. Security researchers tracking internet-facing FortiMail deployments have estimated that several thousand instances remain reachable from the public internet through exposed webmail or management interfaces, though Fortinet has not published its own count of affected or compromised systems, and that figure should be treated as an outside estimate rather than a confirmed number.
This is also not the first time FortiMail or other Fortinet edge products have been targeted by capable attackers shortly after disclosure. Internet-facing security appliances — firewalls, VPN gateways, and email security platforms alike — have become a favored target precisely because they sit at the network perimeter with elevated trust, and because exploitation doesn't require tricking a user into clicking anything. The pattern mirrors other zero-day vulnerabilities disclosed with exploitation already underway, including the Citrix NetScaler SAML flaw patched weeks earlier and the Adobe Commerce vulnerability exploited in September.
Timeline of the disclosure
| Date | Event |
|---|---|
| October 1, 2026 | Fortinet publishes PSIRT advisory FG-IR-26-175 disclosing CVE-2026-104286 and confirming active exploitation in the wild. |
| October 1, 2026 | CISA adds CVE-2026-104286 to its Known Exploited Vulnerabilities catalog. |
| October 4, 2026 | CISA's remediation deadline for U.S. federal civilian agencies under Binding Operational Directive 26-04. |
| October 5, 2026 | Fortinet updates the advisory with fixed releases (8.0.2, 7.6.7, 7.4.9) across the 8.0, 7.6, and 7.4 branches. |
How to check if your FortiMail system has been compromised
Because the flaw allows arbitrary file writes without authentication, Fortinet's advisory recommends administrators look for unexpected or recently modified files on the appliance, particularly around the webmail and IBE components, rather than assuming the absence of an obvious outage means the system is clean. The advisory includes specific indicators of compromise — associated IP addresses and a short list of system files known to have been added or altered in observed attacks — that FortiMail administrators should cross-reference directly against Fortinet's published advisory and their own system logs.
Organizations that cannot rule out compromise, or that find matching indicators, should treat the appliance as potentially compromised: isolate it from the network, preserve logs and disk images for forensic review, and follow CISA's forensic triage guidance before simply patching and moving on, since a patch alone does not remove a foothold an attacker may have already planted.
How to patch and mitigate FortiMail now
Fortinet's guidance is split between a permanent fix and temporary workarounds for systems that can't be patched immediately:
- Patch first, where possible. Upgrade to FortiMail 8.0.2, 7.6.7, or 7.4.9 depending on your current branch. Organizations on 7.2.x should move directly to 7.4.9 or later, since no 7.2 fix is planned.
- Disable IBE if you can't patch immediately. Fortinet's workaround instructs administrators to turn off FortiMail's identity-based encryption feature, which removes the exposed component the attacks have been using.
- Restrict access to the management interface and webmail portal. Block direct internet access to these interfaces and limit access to a trusted internal network or VPN rather than exposing them publicly.
- Add a WAF rule as a stopgap. Where available, block POST requests to the affected IBE path that contain directory-traversal sequences, as an interim layer while the upgrade is scheduled.
Federal civilian agencies were required to complete remediation, or take the product offline, by October 4, 2026 under CISA's directive. Private-sector organizations are not bound by that deadline, but given confirmed exploitation and the low complexity of the attack, Fortinet and CISA are both effectively recommending the same urgency for any organization running FortiMail.
Why this matters
FortiMail is a widely deployed email security gateway used by organizations to filter phishing, spam, and malware before it reaches employee inboxes — which means the appliance itself typically sits with privileged visibility into an organization's email flow and, in many deployments, direct exposure to the internet so it can receive mail. A pre-authentication vulnerability that can be turned into code execution on that kind of system is a high-value target: a successful compromise could, in principle, give an attacker a foothold inside the network perimeter and visibility into sensitive email traffic, not just control of a single appliance.
The disclosure also fits a broader pattern this year of security vendors' own perimeter products — the tools organizations buy specifically to defend their network edge — becoming the entry point attackers use instead. Security teams that would normally treat a security vendor's product as inherently trustworthy are increasingly having to patch and monitor those same products with the same urgency as any other internet-facing system.
What FortiMail admins should do next
If your organization runs FortiMail, treat this as an active-incident response task rather than routine patch management:
- Identify every FortiMail instance in your environment and its current version.
- Check whether the management interface or webmail portal is reachable from the public internet; if so, restrict it immediately regardless of patch status.
- Apply the fixed release for your branch (8.0.2, 7.6.7, or 7.4.9) as soon as it can be scheduled; 7.2.x users should plan a branch upgrade rather than wait for a point release.
- Review logs and the filesystem for the indicators of compromise listed in Fortinet's advisory before and after patching.
- If you cannot patch immediately, disable IBE and lock down network access as an interim measure, and revisit the system as soon as the upgrade window opens.
Fortinet's advisory, hosted on its own PSIRT portal, will remain the authoritative source for further updates, including any additional fixed releases or newly identified indicators of compromise as the investigation continues.
Frequently asked questions
Is CVE-2026-104286 a zero-day? Yes. Fortinet disclosed the vulnerability and confirmed it had already been exploited in the wild in the same advisory, meaning attackers were using it before a patch existed for most affected versions.
Do I need to be logged in for my FortiMail system to be at risk? No. The vulnerability requires no authentication; an attacker only needs network access to a vulnerable FortiMail instance's webmail or management interface.
Is there a patch available? Yes, for the 7.4, 7.6, and 8.0 branches (versions 7.4.9, 7.6.7, and 8.0.2). FortiMail 7.2.x has no dedicated fix; Fortinet recommends upgrading to 7.4 or later instead.
What should I do if I can't patch right away? Disable the IBE feature and block internet access to the management interface and webmail portal until you can apply the update.
Frequently asked questions
Is CVE-2026-104286 a zero-day?
Yes. Fortinet disclosed the vulnerability and confirmed it had already been exploited in the wild in the same advisory, meaning attackers were using it before a patch existed for most affected versions.
Do I need to be logged in for my FortiMail system to be at risk?
No. The vulnerability requires no authentication; an attacker only needs network access to a vulnerable FortiMail instance's webmail or management interface.
Is there a patch available?
Yes, for the 7.4, 7.6, and 8.0 branches (versions 7.4.9, 7.6.7, and 8.0.2). FortiMail 7.2.x has no dedicated fix; Fortinet recommends upgrading to 7.4 or later instead.
What should I do if I can't patch right away?
Disable the IBE feature and block internet access to the management interface and webmail portal until you can apply the update.
What is CVE-2026-104286's CVSS score?
9.8 out of 10, rated Critical. The vulnerability is network-exploitable, requires low attack complexity, and needs no privileges or user interaction to exploit.
Did CISA require federal agencies to patch this?
Yes. CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1, 2026, and set an October 4, 2026 remediation deadline for U.S. federal civilian agencies.
Sources
- Fortinet PSIRT Advisory FG-IR-26-175fortiguard.fortinet.com
- CISA Known Exploited Vulnerabilities Catalogcisa.gov
- NVD: CVE-2026-104286nvd.nist.gov
- The Hacker News: Critical FortiMail zero-day flawthehackernews.com
- Help Net Security: Critical FortiMail zero-day exploited in the wildhelpnetsecurity.com
- Fortinet: FortiMail product pagefortinet.com
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


.jpg)