Fortinet warns of critical FortiMail zero-day CVE-2026-104286 exploited in attacks
Fortinet disclosed an actively exploited FortiMail flaw rated 9.8 that lets unauthenticated attackers write arbitrary files; CISA added it to KEV with an October 4 deadline.
At a glance
- CVE-2026-104286 (CVSS 9.8) is a path traversal and NULL byte handling flaw in FortiMail's management interface.
- Fortinet and CISA confirm in-the-wild exploitation; CISA gave federal agencies until October 4 to act.
- FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6 and 8.0.0–8.0.1 are affected.
- Workarounds include disabling IBE and removing internet access to the management interface; IoCs have been published.
Fortinet has warned customers that a critical vulnerability in its FortiMail email security gateway, tracked as CVE-2026-104286, is being exploited in zero-day attacks. According to BleepingComputer and The Hacker News, the flaw carries a CVSS score of 9.8 and allows an unauthenticated attacker to write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the bug to its Known Exploited Vulnerabilities (KEV) catalog, making it one of the most urgent patching priorities for organizations running FortiMail.
What happened
In its advisory, Fortinet describes the issue as a combination of improper limitation of a pathname to a restricted directory (CWE-22) and improper neutralization of NULL bytes (CWE-158) in the FortiMail management interface. The Hacker News reports that the flaw was discovered internally by Gwendal Guégniaud of Fortinet's product security team. SecurityWeek notes that successful exploitation could potentially give attackers arbitrary code or command execution, but neither Fortinet nor CISA has shared details about the attacks or the threat actors behind them.
According to BleepingComputer and The Hacker News, federal civilian agencies were given until October 4, 2026, to apply mitigations. SecurityWeek reports that this three-day window follows CISA's binding operational directive for exploited flaws.
Who is affected
The following FortiMail branches are vulnerable, according to the advisory as reported by all three outlets:
7.2.0through7.2.97.4.0through7.4.87.6.0through7.6.68.0.0through8.0.1
Fixes are tied to versions 7.4.9, 7.6.7 and 8.0.2. BleepingComputer and SecurityWeek describe these releases as upcoming, while The Hacker News advises upgrading to them or later; administrators should confirm availability on Fortinet's support portal. According to The Hacker News, users of the 7.2 branch should migrate to 7.4 or later.
Technical details and indicators
Fortinet published indicators of compromise to help defenders hunt for intrusions. According to BleepingComputer, these include newly added files such as /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice and /data/etc/ld.so.preload, as well as modifications to /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz. Two attacker IP addresses were listed: 79.141.169[.]187 and 45.129.0[.]192. BleepingComputer adds that log analysis showed attackers configuring an archive account named archive234 to send data to the first of those addresses.
What to do
Until patched builds are installed, Fortinet recommends disabling the IBE (Identity-Based Encryption) feature via the CLI and restricting access to the FortiMail management interface to trusted private networks, removing any internet exposure. Organizations should also check devices against the published file and network indicators, review archive account settings for unknown entries, and treat any device showing signs of compromise as breached, including rotating credentials that pass through the gateway.
Related CVEs
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



