TL;DR
Attackers are exploiting CVE-2026-104286, a CVSS 9.8 FortiMail vulnerability that lets unauthenticated users write arbitrary files. CISA added it to its Known Exploited Vulnerabilities catalog on October 1. Fixed builds are not out yet, so admins must apply Fortinet’s workaround now.
- CVE: CVE-2026-104286
- CVSS: 9.8 (Critical · CVSSv3)
- Product: Fortinet FortiMail
- Affected: 8.0.0, 7.6.0, 7.4.0, 7.2.0, 7.0.0
- Impact: CWE-22
- Status: Exploited in the wild
- Action: See vendor advisory
Tired of noisy Fortinet CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysWhy It Matters
Fortinet confirms the threat in its advisory. It says the flaw “has been reported to be exploited in the wild.” Soon after, CISA added the bug to its KEV catalog, citing “evidence of active exploitation.” Federal agencies have until October 4 to act.
FortiMail guards email for many large firms. As a result, a hijacked gateway can expose mail traffic and give attackers a foothold inside the network. Fortinet appliances also rank among the most targeted edge devices. Their bugs often land in the KEV catalog within days of disclosure.
How the Attack Works
The FortiMail vulnerability combines path traversal (CWE-22) with poor handling of NULL bytes (CWE-158). An attacker sends crafted HTTP or HTTPS requests. The flaw then lets them write files outside the intended folder. Fortinet lists the impact as the ability to “execute unauthorized code or commands.” HOL reports that the bug sits in the GUI’s Identity Based Encryption (IBE) component.
Affected Versions
- FortiMail 8.0.0
- FortiMail 7.6.0 through 7.6.5
- FortiMail 7.4.0 through 7.4.6
- FortiMail 7.2.0 through 7.2.9
- FortiMail 7.0.0 through 7.0.9
Patch and Mitigation Steps
Apply the Workaround
The Fortinet FG-IR-26-175 advisory urges customers to apply its workaround. HOL says this means disabling IBE, or limiting management access to trusted internal networks.
Plan the Upgrade
HOL lists fixes coming in 8.0.2, 7.6.7, and 7.4.9. Users on 7.2 should move to 7.4 or later. The advisory names no fix for the 7.0 branch, so those users should plan a migration too.
Hunt for Compromise
Finally, check exposed appliances for changed binaries, odd library preloads, and outbound traffic to unknown hosts.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!