Fortinet and CISA Warn of Actively Exploited FortiMail Flaw

Critical vulnerability CVE-2026-104286 in FortiMail allows unauthenticated file writing. Fortinet confirmed its exploitation, and CISA added it to the KEV catalog.

FortiMail CVE-2026-104286 is a critical vulnerability warned about by both Fortinet and the U.S. agency CISA. In advisory FG-IR-26-175, the manufacturer confirmed that the flaw is being actively exploited. An attacker can use it without logging in to write arbitrary files to an affected system through a modified HTTP or HTTPS request.

CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities (KEV) catalog on October 1, 2026. The addition means that exploitation of the flaw has been confirmed in practice; it is not merely a theoretical security problem.

What is FortiMail CVE-2026-104286?

According to Fortinet, this is an unauthenticated path traversal vulnerability combined with improper handling of a null character. In path traversal attacks, an attacker can manipulate a file path to access locations that would not normally be available.

In this case, a maliciously modified HTTP or HTTPS request can lead to arbitrary file writing on the device. Fortinet states that this could result in further control of the system. Internet-accessible administrative interfaces on vulnerable installations are particularly risky.

The flaw affects these FortiMail versions:

  • FortiMail 8.0.0 through 8.0.1,
  • FortiMail 7.6.0 through 7.6.6,
  • FortiMail 7.4.0 through 7.4.8,
  • FortiMail 7.2.0 through 7.2.9.

Recommended steps for administrators

As a temporary measure, Fortinet recommends disabling IBE or restricting access to the administrative interface exclusively to trusted private networks. Administrators should also check the indicators of compromise and logs listed in the manufacturer’s advisory.

Fixed releases FortiMail 7.4.9, 7.6.7, and 8.0.2 were announced as forthcoming at the time of publication. Before updating, it is therefore necessary to verify the current status and availability of the specific fix directly in Fortinet’s advisory.

For U.S. federal agencies, CISA set a deadline of October 4, 2026, for risk mitigation and forensic review. Organizations outside the U.S. federal government are not directly bound by this deadline, but confirmed active exploitation increases the urgency of checking affected devices.

Why a flaw in an email gateway is sensitive

FortiMail serves as an email security gateway. Compromise of such a device could give an attacker a foothold in corporate infrastructure and provide access to sensitive email flows or configuration.

Fortinet has not yet disclosed when exploitation began, how many devices were compromised, or the identity of the attackers. The number of victims and any connection to a specific ransomware campaign have also not been publicly confirmed.

The next developments to watch are the release of fixed versions, any technical updates from Fortinet about the scope of the attacks, and the results of log reviews by organizations operating the affected versions.

Sources

  • Fortinet PSIRT FG-IR-26-175 – Confirms the technical nature of the flaw, affected versions, exploitation in practice, and recommended mitigations.
  • CISA Known Exploited Vulnerabilities Catalog – Confirms that CVE-2026-104286 was added to KEV on October 1, 2026, along with the requirement for mitigation and forensic review.
  • BleepingComputer – Independently summarizes the Fortinet advisory, the patch status, and limited public information about the attacks.

Verified and updated: 10/02/2026 06:20

Sharing