Skip to content
TrustList
News

Fortinet ships FortiMail fixes for exploited flaw CVE-2026-104286

Editorial

By TrustList Editorial

Fortinet's advisory FG-IR-26-175 was updated on 7 October with fixed builds for three branches. FortiMail 7.2 gets no fix and must move to 7.4 or later; Cloud is already patched.

About Fortinet ships FortiMail fixes for exploited flaw CVE-2026-104286

Fortinet ships FortiMail fixes for exploited flaw CVE-2026-104286

7 October 2026: Fortinet has fixed CVE-2026-104286, a critical flaw (CVSS 9.8) in FortiMail that lets an attacker who is not logged in write arbitrary files to the appliance with crafted HTTP or HTTPS requests. The advisory, FG-IR-26-175, says the bug has been reported as exploited in the wild. It was published on 1 October and updated on 7 October, and the update is the one that lists the upgrade targets. Our first report covered the flaw while fixes were still pending.

Not yet independently verified. Based on Fortinet's advisory page as read on 9 October 2026. Fortinet does not say when exploitation began or how many appliances were hit. We will update this when it can be confirmed, and remove this note.

The flaw combines path traversal (CWE-22) with improper handling of NULL bytes (CWE-158). Fortinet lists the impact as execution of unauthorised code or commands. The company says its own product security team found it, crediting Gwendal Guegniaud, and it lists no virtual patch.

Which versions to move to:

  • FortiMail 8.0.0 to 8.0.1: upgrade to 8.0.2 or later
  • FortiMail 7.6.0 to 7.6.6: upgrade to 7.6.7 or later
  • FortiMail 7.4.0 to 7.4.8: upgrade to 7.4.9 or later
  • FortiMail 7.2.0 to 7.2.9: no fixed 7.2 build, move to the 7.4 branch or later

FortiMail Cloud has already been fixed by Fortinet, so cloud customers need do nothing.

If an appliance cannot be upgraded yet, Fortinet gives three workarounds. The first is to disable the IBE (identity-based encryption) service, under Encryption > IBE in the GUI or with the CLI command config system encryption ibe set status disable. The second is to stop the webmail interface being reachable from the internet, or limit it to trusted private networks. The third, for sites with a web application firewall in front, is to block POST requests to /ibe that contain ../.

Fortinet lists several signs of compromise. These are unexpected root cron entries that run shell commands, admin CLI activity that adds an archive account pointing at a remote destination, and IBE decryption errors together with failed logins by internal users in the encryption logs. The advisory also lists source IP addresses, which the page renders in a run-together form, so check them against the CSAF or STIX download before blocking anything.

Fortinet has not said when the exploitation began.

Company profile on TrustList: Fortinet

Related on TrustList:

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy