NEWS

Critical FortiMail Zero-Day CVE-2026-104286 Actively Exploited, No Patch Yet

CISA added CVSS 9.8 FortiMail flaw CVE-2026-104286 to its KEV catalog after active exploitation; Fortinet has no fix, only workarounds.

Dylan H.

News Desk

October 2, 2026
5 min read
Critical FortiMail Zero-Day CVE-2026-104286 Actively Exploited, No Patch Yet

Unauthenticated Path Traversal Flaw Lets Attackers Write Arbitrary Files to FortiMail Systems

Fortinet's FortiMail secure email gateway is affected by a critical zero-day vulnerability, tracked as CVE-2026-104286, that is being actively exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on October 1, 2026, giving Federal Civilian Executive Branch agencies until October 4, 2026 to remediate under Binding Operational Directive 26-04. Fortinet published its own advisory, FG-IR-26-175, the same day, crediting the find to Gwendal Guégniaud of Fortinet's Product Security team.

As of publication, Fortinet has not yet released a patched build for any affected branch — only interim workarounds are available, making this an active zero-day in the truest sense: exploitation predates a fix.


Vulnerability Details

AttributeValue
CVE IDCVE-2026-104286
CVSS v3.1 Score9.8 (Critical)
Weakness ClassCWE-22 (Path Traversal) combined with CWE-158 (improper neutralization of NULL byte/character)
Affected ProductFortinet FortiMail
Primary ImpactUnauthenticated arbitrary file write; potential arbitrary code/command execution
Attack VectorCrafted HTTP/HTTPS requests to the FortiMail interface
Authentication RequiredNone
Discovered ByGwendal Guégniaud, Fortinet Product Security team (internal discovery)
Fortinet AdvisoryFG-IR-26-175 (published October 1, 2026)
CISA KEV ListedYes — added October 1, 2026
Federal Remediation DeadlineOctober 4, 2026 (BOD 26-04)
Patch AvailabilityNone at time of publication — fixed builds still forthcoming

Affected Versions

FortiMail BranchAffected VersionsFix Status
8.08.0.0 – 8.0.1Upcoming 8.0.2 (not yet released)
7.67.6.0 – 7.6.6Upcoming 7.6.7 (not yet released)
7.47.4.0 – 7.4.8Upcoming 7.4.9 (not yet released)
7.27.2.0 – 7.2.9No fix planned for this branch — migration to 7.4+ required

Fortinet's advisory is the authoritative source for current fix status, since machine-readable CVE affected-version metadata circulating in third-party feeds has been reported to conflict with the live advisory. Administrators should check FG-IR-26-175 directly rather than relying on a cached scanner feed.


How the Flaw Works

CVE-2026-104286 combines a path traversal weakness with improper neutralization of NULL bytes/characters, allowing a remote, unauthenticated attacker to send crafted HTTP or HTTPS requests to FortiMail that cause the system to write arbitrary files outside their intended directory. Depending on where a malicious file lands, this can be chained into arbitrary code or command execution on the underlying system — a textbook critical-severity outcome for a flaw with no authentication requirement, reachable over the network.

Fortinet's own incident data points to active, hands-on-keyboard exploitation: the company has identified indicators of compromise including two attacker-controlled IP addresses and seven suspicious files, among them modified system binaries and newly injected libraries — consistent with attackers using the file-write primitive to drop persistence mechanisms or backdoors on compromised appliances.


Mitigations (No Patch Available)

Because no fixed build currently exists for any affected branch, Fortinet's guidance is workaround-only:

  1. Disable Identity-Based Encryption (IBE) feature support on affected FortiMail systems, which Fortinet identifies as implicated in the vulnerable code path.
  2. Restrict access to the FortiMail management interface to trusted internal networks only — remove it from direct public internet exposure.
  3. Hunt for the published indicators of compromise: check for connections from the two IoC IP addresses, and audit system binaries and loaded libraries against known-good baselines for signs of the seven identified suspicious files or similar tampering.
  4. FortiMail 7.2.x administrators should plan migration to the 7.4 branch or later, since Fortinet has indicated no fix is planned for 7.2.x directly.
  5. Monitor Fortinet's FG-IR-26-175 advisory for the release of 7.4.9, 7.6.7, and 8.0.2, and apply them immediately once available.

Impact Assessment

Impact AreaDescription
Confidentiality / IntegrityArbitrary file write can plant backdoors, web shells, or modified binaries, giving attackers a durable foothold on the mail gateway
AvailabilityA compromised FortiMail appliance sits in the inbound/outbound mail path — tampering can disrupt or redirect organizational email flow
ScopeFortiMail is a perimeter-facing secure email gateway by design, making this a direct bridge from the public internet into email infrastructure
Federal ExposureCISA's KEV listing and three-day BOD 26-04 deadline reflect confirmed active exploitation against federal and likely broader targets
Patch GapWith no fixed build yet released, every affected deployment remains exposed until Fortinet ships 7.4.9 / 7.6.7 / 8.0.2 — workarounds are the only current defense

Key Takeaways

  1. CVE-2026-104286 is a CVSS 9.8 critical, unauthenticated path-traversal/file-write flaw in Fortinet FortiMail, actively exploited in the wild.
  2. CISA added it to the KEV catalog on October 1, 2026, giving federal agencies until October 4 to remediate.
  3. No patched version exists yet for any affected branch (7.2, 7.4, 7.6, 8.0) — Fortinet's advisory FG-IR-26-175 lists 7.4.9, 7.6.7, and 8.0.2 as forthcoming but unreleased.
  4. FortiMail 7.2.x has no planned fix; administrators on that branch must migrate to 7.4 or later.
  5. Fortinet has published indicators of compromise (two attacker IPs, seven suspicious files including modified binaries) from its own investigation of in-the-wild exploitation.
  6. Until a patch ships, organizations must rely on workarounds: disabling IBE support and restricting management-interface access to trusted networks.

Sources