Fortinet has disclosed a critical vulnerability in FortiMail, its email security gateway, and says attackers are already exploiting it. The flaw, tracked as CVE-2026-104286, lets an unauthenticated attacker write arbitrary files to the appliance's underlying system using crafted HTTP or HTTPS requests. Fortinet published its advisory on October 1, 2026, without a fixed release ready to download, and pointed customers to a workaround.
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog the same day.
What Fortinet disclosed
Fortinet's advisory, FG-IR-26-175, describes the bug as a combination of two weaknesses: path traversal (improper limitation of a pathname to a restricted directory) and improper neutralization of NULL bytes. Fortinet rates it Critical, with a CVSSv3 score of 9.8, and classes it as exploitable without authentication.
The vulnerable code is in FortiMail's Identity-Based Encryption (IBE) feature. Appliances with IBE enabled and the management interface reachable from the internet are the most exposed.
The file write is the entry point, not the end state. Writing files to certain locations on the appliance can let an attacker execute code or commands, The Register reported. Security researchers quoted by Cybersecurity Dive said a compromised gateway can give attackers access to credentials, stored mail and other connected systems.
The advisory says the flaw is being exploited in the wild. According to The Register, it does not say when the attacks began, who is behind them or how many customers have been compromised. Fortinet has published indicators of compromise, including suspicious files, configuration changes and IP addresses associated with the activity.
A Fortinet spokesperson told Cybersecurity Dive that the company is "communicating with relevant government organizations, including CISA, on the content of this advisory."
Who is affected
Fortinet lists four affected release branches, as reported by BleepingComputer and Help Net Security:
- FortiMail 8.0.0 through 8.0.1
- FortiMail 7.6.0 through 7.6.6
- FortiMail 7.4.0 through 7.4.8
- FortiMail 7.2.0 through 7.2.9
Belgium's Centre for Cybersecurity (CCB) also names the 7.0 branch in its advisory. Fortinet's own advisory is the reference for version scope, and organisations still running 7.0 should confirm their status with Fortinet directly.
CISA gave US federal civilian executive branch agencies until October 4, 2026, to apply the vendor's mitigations. That deadline binds only those agencies. For everyone else, the KEV listing means CISA has evidence of active exploitation, not just a theoretical risk.
What administrators can do now
Fortinet says the fixes will ship in FortiMail 8.0.2, 7.6.7 and 7.4.9. Fortinet has not announced a fix on the 7.2 branch. Customers on 7.2 are directed to move to a fixed 7.4 release, according to Field Effect.
Until a fixed release is installed, the advisory offers two workarounds:
- Disable IBE support through the GUI or the CLI (
config system encryption ibe, thenset status disable). - Remove internet access to the FortiMail management interface, or restrict it to trusted private networks.
Either step reduces exposure going forward. Neither one removes anything an attacker may already have written to the appliance. The CCB advises organisations to check whether their devices were compromised before the workaround went in, and Fortinet's published indicators are the starting point for that check.
The patch status is not settled
When the advisory went live, Fortinet listed 8.0.2, 7.6.7 and 7.4.9 as upcoming releases and gave no timeline, according to The Register and BleepingComputer.
Reports since then do not agree. Security firm Hard2bit reported on October 5 that Fortinet's documentation carried release notes for 7.6.7, dated October 2, and 7.4.9, dated October 3, while the advisory still described both as upcoming. Hard2bit said it could not confirm that 8.0.2 had been published.
Singapore's Cyber Security Agency issued alert AL-2026-133 on October 6. The alert says Fortinet has released security updates. It also tells users to apply the workarounds and update "once these are available."
TechShorts could not independently confirm, as of October 6, which of the three fixed releases are available for download. Administrators should check the FG-IR-26-175 advisory and Fortinet's support portal for their specific branch before assuming a fix exists.
What to watch
The next concrete signal is a revision to FG-IR-26-175 that marks 8.0.2, 7.6.7 and 7.4.9 as released. Fortinet has not said whether it will issue any fix on the 7.2 branch, so customers on 7.2 should plan for a version migration rather than a patch.
Fortinet has not disclosed how the attacks began or how many organisations were hit. Any update to the advisory's exploitation details or indicators of compromise should prompt affected organisations to run their compromise checks again.
