FortiMail zero-day (CVE-2026-104286) exploited in the wild before a patch is available
Fortinet disclosed CVE-2026-104286, a critical FortiMail flaw exploited in the wild to write arbitrary files to email gateways, prompting an emergency CISA patching order.
- Victim
- Fortinet FortiMail
On 1 October 2026, Fortinet β the Sunnyvale-based network and email security vendor β disclosed CVE-2026-104286, a critical vulnerability in its FortiMail secure email gateway that was already being exploited in the wild at the time of disclosure. Published in advisory FG-IR-26-175 and rated 9.8 on the CVSS scale, the flaw lets an unauthenticated attacker write arbitrary files to an affected appliance by sending specially crafted HTTP or HTTPS requests β a foothold that can be escalated to full compromise of the mail gateway.
The bug combines a path-traversal weakness with improper handling of null characters in FortiMail's web interface, specifically reachable through its Identity-Based Encryption (IBE) feature. Fortinet's advisory states plainly that the vulnerability "has been reported to be exploited in the wild" and marks it as known-exploited, making it a true zero-day: defenders learned of the flaw and its active abuse on the same day.
Affected versions
The vulnerability affects multiple supported FortiMail branches: 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. At the time of disclosure, fixed builds for the affected branches were listed as upcoming rather than available, leaving many organisations dependent on workarounds. Fortinet advised customers to disable IBE support or restrict access to the FortiMail management interface from the internet until patches ship.
Emergency response
The same day, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, setting a remediation deadline of 4 October 2026 for federal civilian agencies β an unusually short window reflecting the severity and ongoing exploitation. Email security gateways are high-value targets because they sit at the perimeter, process untrusted inbound traffic, and often hold credentials and message archives; a write-anywhere primitive on such a device is close to a worst-case scenario.
Why it matters
No specific threat actor or set of victim organisations had been publicly identified at the time of disclosure, and the incident remains ongoing: attackers are actively exploiting internet-facing FortiMail appliances while comprehensive patches are still being rolled out. The episode continues a well-worn pattern in which perimeter security appliances β VPNs, firewalls, and mail gateways β are themselves turned into entry points, and underscores why exposed management interfaces should never be reachable from the open internet.
Timeline
Fortinet publishes advisory FG-IR-26-175, disclosing CVE-2026-104286 and warning it is being exploited in the wild.
CISA adds CVE-2026-104286 to its Known Exploited Vulnerabilities catalog.
CISA's remediation deadline for U.S. federal civilian agencies.
Sources
- fortiguard.fortinet.comhttps://fortiguard.fortinet.com/psirt/FG-IR-26-175
- cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-104286
- securityweek.comhttps://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/
- socradar.iohttps://socradar.io/blog/fortimail-zero-day-under-active-exploitation/