FORTIMAIL IS BEING HACKED RIGHT NOW — CVE-2026-104286 IS A LIVE ZERO-DAY
- The Mess: Fortinet confirmed that attackers are actively exploiting a critical FortiMail flaw that needs no credentials and can write arbitrary files to the underlying system. The bug is tracked as CVE-2026-104286 and carries a CVSS 9.8 score.
- The Damage: A compromised FortiMail sits directly inside the email path, giving an attacker a potentially powerful foothold on an internet-facing security appliance.
- The Fix: Disable Identity-Based Encryption (IBE), restrict the FortiMail management interface to trusted networks, investigate for compromise, then install the fixed firmware as soon as Fortinet releases it.
FortiMail is supposed to sit between the internet and corporate mail infrastructure and inspect hostile input all day. CVE-2026-104286 attacks that exact position.
The vulnerability combines a path traversal issue (CWE-22) with improper handling of NULL characters (CWE-158). A specially crafted HTTP or HTTPS request can allow an unauthenticated attacker to write arbitrary files on the underlying system. Fortinet has confirmed that the vulnerability is already being exploited in the wild.
That is the important part.
This isn’t a theoretical bug waiting for somebody to build an exploit.
Someone is already using it.
The exposed versions
The affected FortiMail branches are:
- 8.0.0 – 8.0.1
- 7.6.0 – 7.6.6
- 7.4.0 – 7.4.8
- 7.2.0 – 7.2.9
Fortinet lists 8.0.2, 7.6.7 and 7.4.9 as the upcoming fixed releases. For the 7.2 branch, administrators are directed toward the 7.4 branch or later. As of October 3, the fixed releases were still described as upcoming in the available vendor-linked advisories.
That leaves administrators in an unpleasant position: the vulnerability is being exploited, but affected installations may not yet have a firmware update available.
The workaround
Fortinet’s immediate workaround is to disable the Identity-Based Encryption feature:
config system encryption ibe
set status disable
end
Administrators should also remove public access to the FortiMail management interface wherever possible and restrict it to trusted private networks.
This matters because the vulnerability is unauthenticated.
If an attacker can reach the vulnerable interface, they don’t need a stolen administrator password to start attacking the appliance.
Don’t stop at mitigation
A workaround prevents or reduces further exploitation.
It does not prove that the appliance wasn’t already compromised.
Fortinet published indicators of compromise alongside the advisory, and CERT Polska explicitly recommends checking vulnerable installations for signs of unauthorized access.
Security teams should therefore treat this as an incident-response problem as well as a patching problem:
- Identify every affected FortiMail appliance.
- Determine whether its management interface was reachable from untrusted networks.
- Disable IBE if it is not immediately required.
- Restrict management access to trusted networks.
- Review logs and Fortinet’s published IoCs.
- Preserve evidence before wiping or rebuilding a potentially compromised appliance.
- Install the appropriate fixed release as soon as it becomes available.
CVE-2026-104286 has also been added to the U.S. CISA Known Exploited Vulnerabilities catalog, reinforcing that this is not a vulnerability to park in a ticket queue for next month’s maintenance window.
Why this one matters
Security appliances are attractive targets because they are supposed to be trusted.
They sit on the edge.
They process untrusted traffic.
They often have access to sensitive infrastructure.
And when the appliance is an email security gateway, compromise can put the organization’s communications infrastructure directly in the attacker’s reach.
The CVSS number is almost irrelevant once active exploitation is confirmed.
The important number is zero.
Zero credentials required.
That’s the real problem with CVE-2026-104286.
Bugstoday opinion: An internet-facing FortiMail appliance with an actively exploited, unauthenticated file-write vulnerability isn’t a normal patching task. It is an incident-response problem waiting for an owner. If you run one of the affected versions, check exposure and compromise indicators now — then patch the moment the fixed firmware lands.
Technical Sources
- Fortinet PSIRT — FG-IR-26-175
- CVE-2026-104286 — CVE.org
- CERT Polska — FortiMail actively exploited vulnerability
- CERT-FR — FortiMail vulnerability advisory
- CISA Known Exploited Vulnerabilities




