Fortinet warns of critical FortiMail zero-day flaw
Fortinet has issued an urgent warning regarding a critical vulnerability in its FortiMail email security product that is currently being exploited in the wild. The flaw allows unauthenticated attackers to write arbitrary files to the system, posing a severe risk to enterprise email infrastructure.

Critical Vulnerability Disclosed
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. The company published an advisory detailing the severity of the issue, which affects the management interface of the email security appliance. According to the report, the flaw carries a CVSS score of 9.8, placing it in the critical severity category. This high rating reflects the ease with which an attacker can exploit the weakness without needing prior authentication to the system. Further details are available from BleepingComputer in the original source material.
Technical Details of the Flaw
The vulnerability is described as a combination of an Improper Limitation of a Pathname to a Restricted Directory, known as Path Traversal, and Improper Neutralization of NULL Byte or NULL Character. Fortinet explained that these weaknesses may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. The internal discovery of the bug by Gwendal Guégniaud of Fortinet's Product Security team highlights the company's ongoing efforts to identify and address security gaps within its product lineup. The specific combination of these coding errors creates a significant attack vector for malicious actors targeting enterprise email gateways.
Affected Versions and Scope
The flaw affects a wide range of FortiMail versions, including 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Users of the older 7.2 branch can patch the vulnerability by upgrading to the 7.4 branch or later. However, for installations running FortiMail 7.4, 7.6, and 8.0, security updates are not yet available at the time of the advisory. Fortinet has listed FortiMail 7.4.9, 7.6.7, and 8.0.2 as upcoming versions that will contain the necessary fix. This delay in patch availability for the latest branches necessitates immediate interim measures to protect systems from active exploitation.
Recommended Mitigation Strategies
Until patched versions are available, Fortinet urges administrators to apply shared workarounds to mitigate the risk. One recommended method is disabling IBE feature support using specific command-line instructions provided in the security guidance. As an alternative, administrators can disable access to the FortiMail management interface from the Internet or restrict access to trusted private networks only. These steps aim to reduce the attack surface exposed to potential attackers while the company works to finalize and distribute the official security updates. Implementing these controls is critical for organizations that cannot immediately upgrade their software versions.
Indicators of Compromise
Fortinet has published indicators of compromise (IOCs) associated with the attacks to help defenders identify potentially compromised systems. These include specific files that were added or modified on affected appliances, as well as IP addresses 79[.]141.169.187 and 45[.]129.0.192 linked to the malicious activity. The advisory also includes log entries that administrators can use to detect intrusion attempts. One notable log entry shows an archive account named archive234 being configured from the command line with 79.141.169.187 as the remote server and /uploads as the remote directory. This suggests that attackers may have configured compromised devices to exfiltrate archived data to external servers.
Regulatory Response and Coordination
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-104286 to its Known Exploited Vulnerability catalog. Federal agencies are required to perform forensic triage and mitigate the flaw by October 4th. Fortinet stated that it is coordinating with government agencies, including CISA, regarding the content of the advisory. The company emphasized its commitment to responsible disclosure and public-private partnerships in addressing the threat. While Fortinet has not disclosed when the flaw was first exploited or who is behind the attacks, the involvement of CISA underscores the significant risk this vulnerability poses to national and enterprise security infrastructure.
Sources
- BleepingComputerFortinet warns of critical FortiMail flaw exploited in zero-day attacks