The Daily Newsstand · Free, Always
Friday, October 2, 2026

Fortinet sounds the alarm over actively exploited FortiMail zero-day

Translate

No login required, exploitation underway, and some admins are still waiting for patches

Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in.

The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform.

Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system.

REG AD

Writing files to certain locations could allow an attacker to execute code or commands on the appliance.

REG AD

Fortinet says the flaw affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.

The vendor's advisory says CVE-2026-104286 "is being exploited in the wild," although it doesn't say when the attacks began, who is behind them, or how many customers may have been compromised.

It has, however, published indicators administrators can hunt for on their systems. These include suspicious files and configuration changes, along with IP addresses associated with the attacks.

CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, directing US federal civilian agencies to carry out forensic triage and apply mitigations by October 4.

Fortinet lists fixes for several affected branches as "upcoming," leaving customers on those versions reliant on workarounds until updates arrive.

In the meantime, Fortinet recommends disabling Identity Based Encryption if it isn't required. Where that's not possible, customers should prevent the FortiMail management interface from being reachable from the internet and restrict access to trusted private networks.

Administrators should also check for signs of compromise: applying a workaround will not remove any files or persistence mechanisms attackers may already have planted.

It's not Fortinet's first encounter with attackers making themselves at home on its network appliances this year. In June, credentials linked to around 75,000 FortiGate firewalls turned up in criminal hands, though Fortinet said the data came from previous incidents and brute-force attacks rather than a fresh breach. ®

View the original on The Register →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.