The short version: On October 1, 2026, Fortinet disclosed CVE-2026-104286, a critical zero-day in FortiMail with a CVSS score of 9.8 that lets unauthenticated attackers write arbitrary files on the appliance through crafted web requests. Fortinet confirmed it is already being exploited in the wild, CISA added it to its Known Exploited Vulnerabilities catalog the same day with an October 4 remediation deadline for US federal agencies, and complete patches are not yet available. If you run FortiMail, disable identity-based encryption or take the management interface off the public internet today.
What is CVE-2026-104286?
FortiMail is Fortinet’s dedicated email security gateway. Companies that find the built-in filters in Microsoft 365 or Google Workspace too basic often put FortiMail in front of their mail flow to catch phishing, malware, and business email compromise attempts. That is what makes this vulnerability so awkward: the device whose job is to protect email is itself the target.
The flaw sits in the FortiMail management interface, specifically in the component that handles identity-based encryption (IBE), the feature that lets users send encrypted email to recipients who do not have their own encryption keys. Two weaknesses combine here: path traversal (CWE-22), where an attacker tricks the software into escaping its intended directory, and improper handling of NULL bytes (CWE-158), which can confuse the security checks that are supposed to block dangerous file paths. Put together, they let someone with no account at all send a crafted HTTP or HTTPS request and write files to the underlying system. Fortinet warns the impact can extend to executing unauthorized code or commands on the appliance.
The flaw was found internally by Gwendal Guégniaud of Fortinet’s Product Security team, and Fortinet published it as advisory FG-IR-26-175 on October 1, 2026.
Which versions are affected?
Fortinet lists four affected branches:
- FortiMail 8.0.0 through 8.0.1 (fix coming in 8.0.2)
- FortiMail 7.6.0 through 7.6.6 (fix coming in 7.6.7)
- FortiMail 7.4.0 through 7.4.8 (fix coming in 7.4.9)
- FortiMail 7.2.0 through 7.2.9 (no patch planned; Fortinet advises upgrading to the 7.4 branch or later)
Here is the uncomfortable part: at the time of disclosure, none of the fixed versions had actually been released. Three of the four affected branches have no patch, only a workaround. If your appliance sits on an affected build and its management interface is reachable from the internet, you should treat it as potentially compromised until you prove otherwise.
This is also the third critical appliance zero-day in about a week. We covered the F5 BIG-IP flaw (CVE-2026-94127) and the Cisco SD-WAN flaw (CVE-2026-76504) days ago, and the pattern is the same every time: an exposed management interface, a critical severity score, active exploitation, and a scramble to patch before attackers find the box.
How attackers are exploiting it
Fortinet states the vulnerability has been reported as exploited in the wild, though it has not published details on who is behind the attacks or how many systems have been hit. To help administrators check their appliances, Fortinet released indicators of compromise: two IP addresses (79.141.169.187 and 45.129.0.192), suspicious files such as /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, and /data/etc/ld.so.preload, plus log entries showing the creation of a suspicious account pointing to a remote server.
The real-world risk goes beyond one company. Many small and mid-sized businesses do not run FortiMail themselves; their managed service provider does. If one provider manages FortiMail for dozens of clients and misses the deadline, a single attacker who finds the provider’s management IPs could hit many businesses in one afternoon. Your email security is only as good as your provider’s patching discipline.
What to do right now
1. Find every FortiMail appliance and check its version
Inventory matters more than panic. Identify every FortiMail unit in your environment, note the exact firmware build on each, and compare against the affected ranges above. Pay special attention to whether the management interface is exposed to the internet.
2. Apply Fortinet’s workaround immediately
Until patched firmware ships, Fortinet recommends disabling IBE support through the CLI:
config system encryption ibe set status disable end
If disabling IBE is not an option for your setup, remove the management interface from the public internet or restrict it to trusted private management networks.
3. Hunt for signs of compromise
Check for the IOC files and IP addresses, review system logs for unexpected account creation, look for changed binaries or odd library preloads, and watch for outbound traffic to unknown hosts. If anything matches, start formal incident response: isolate the appliance, preserve logs before rebooting or re-imaging, and bring in forensic help. There is no virtual patch for this one, so exposure reduction is the only protection until firmware ships.
4. Plan the upgrade now
Watch advisory FG-IR-26-175 for the release of 8.0.2, 7.6.7, and 7.4.9. If you are on the 7.2 branch, start planning the move to 7.4 or later today, since no fix is coming for 7.2. Teams that want to get better at this kind of response should also look at structured training; our roundup of the best cybersecurity courses for beginners is a good starting point for staff who need to build incident response skills.
Why this one stings more than a routine patch
Most vulnerabilities get a patch on day one and a reasonable window to apply it. This one arrived with active exploitation, a CISA deadline three days out, and patches that do not exist yet. Worse, the target is an email security gateway. An attacker who owns your FortiMail does not just see your mail; they sit inside the system that decides which mail is trustworthy. That is a position worth more than a single compromised workstation, and it is exactly why CISA moved this one to the top of the queue.
The broader lesson for anyone running network appliances: management interfaces belong on private networks, not the open internet. Every one of this week’s critical zero-days followed the same playbook, and the cheapest defense against the next one is to make sure your appliances are not reachable from the outside in the first place.
Frequently asked questions
What is CVE-2026-104286?
It is a critical zero-day vulnerability in Fortinet FortiMail, disclosed October 1, 2026, that combines path traversal and NULL-byte injection to let unauthenticated attackers write arbitrary files via crafted web requests. It carries a CVSS score of 9.8.
Has CVE-2026-104286 been exploited?
Yes. Fortinet confirmed it has been reported as exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on October 1, 2026.
What is the CISA deadline?
US federal civilian agencies must remediate it by October 4, 2026. Private organizations have no formal deadline, but attackers do not wait for one, so treat it as urgent.
Is there a patch yet?
Not at disclosure. Fixed versions 8.0.2, 7.6.7, and 7.4.9 were listed as upcoming but unreleased. FortiMail 7.2 users are advised to upgrade to the 7.4 branch or later instead.
What is the workaround?
Disable IBE support with the CLI commands config system encryption ibe, set status disable, end, or take the management interface off the public internet and restrict it to trusted private networks.
Should small businesses worry about this?
Only if you (or your managed service provider) run FortiMail. If your email goes through Microsoft 365 or Google Workspace without a FortiMail gateway, this vulnerability does not touch you. If you are not sure, ask your IT provider directly.
Bottom line
CVE-2026-104286 is about as serious as email security flaws get: unauthenticated, actively exploited, sitting in the device that guards your inbox, with no patch available on day one. Check your versions, apply the workaround, sweep for the indicators of compromise, and get the upgrade planned. The three-day CISA deadline tells you everything about how fast the other side is moving.
