Don’t do SECURITY. Do business SECURELY.

Urgent: Fortinet FortiMail vulnerability under active attack

Fortinet FortiMail flaw CVE-2026-104286 (CVSS 9.8) is being actively exploited: upgrade now, or disable IBE and restrict management access, then check for compromise.

Urgent awareness alert. This is awareness content, not a monitored threat intelligence service: always check vendor advisories against your own environment.

Fortinet has disclosed a critical vulnerability in FortiMail, its email security gateway, that is being exploited in the wild. Tracked as CVE-2026-104286 (CVSS 9.8), the flaw combines a path traversal weakness with improper handling of null bytes. An unauthenticated remote attacker can send crafted HTTP or HTTPS requests to write arbitrary files to the device, which may allow them to run their own code. CISA added it to its Known Exploited Vulnerabilities catalogue on 1 October 2026. Affected versions are FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and all 7.2 releases. Any organisation running FortiMail, especially with its web or management interface reachable from the internet, should act now.

What to do:

  • Upgrade to FortiMail 8.0.2, 7.6.7, or 7.4.9 or later; 7.2 users should move to a fixed 7.4 or later release.
  • If you cannot patch straight away, disable Identity-Based Encryption (IBE) and restrict management interface access to trusted networks only.
  • Check for compromise using the indicators in Fortinet’s advisory, including unexpected or modified files, unexpected archive accounts, failed admin logins, IBE decryption errors, and unusual cron jobs.
  • Remove direct internet exposure of the management interface wherever possible.

Source: Fortinet PSIRT advisory FG-IR-26-175

If you would like help assessing your exposure, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights