FortiMail flaw CVE-2026-104286 is exploited and fixes are still upcoming: disable IBE or close the management interface now
EditorialBy TrustList Editorial
Fortinet says CVE-2026-104286, an unauthenticated file-write flaw in FortiMail rated 9.8, is exploited in the wild. Fixed builds 8.0.2, 7.6.7 and 7.4.9 are listed as upcoming. Disable IBE or restrict the management interface, and check for the indicators.
- Cybersecurity
- Vulnerability Management
- Patch Management
- Email Management
- +2 more
About FortiMail flaw CVE-2026-104286 is exploited and fixes are still upcoming: disable IBE or close the management interface now
FortiMail flaw CVE-2026-104286 is exploited and fixes are still upcoming: disable IBE or close the management interface now
2 October 2026 — Fortinet published advisory FG-IR-26-175 on 1 October 2026 for CVE-2026-104286, a flaw in FortiMail, its email security gateway. Fortinet describes a path-traversal and NULL-byte handling weakness that "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests", and says it has been exploited in the wild. It rates the flaw 9.8 out of 10. The US Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalogue the same day and gave US federal agencies until 4 October to act. BleepingComputer reported it on 1 October and Italy's national CSIRT issued an alert on 2 October.
Affected versions and the fixes
| Branch | Affected | Fix named by Fortinet |
|---|---|---|
| FortiMail 8.0 | 8.0.0 to 8.0.1 | 8.0.2 or later |
| FortiMail 7.6 | 7.6.0 to 7.6.6 | 7.6.7 or later |
| FortiMail 7.4 | 7.4.0 to 7.4.8 | 7.4.9 or later |
| FortiMail 7.2 | 7.2.0 to 7.2.9 | move to 7.4 or later |
When we read the advisory on 2 October, Fortinet listed these fixed builds as upcoming, and the Italian CSIRT also said no fixed release was yet available. Until the build for your branch is published, the workaround is the only protection.
What to do now
- Disable the IBE (Identity-Based Encryption) feature from the CLI if you do not depend on it, as Fortinet's workaround describes.
- Take the management interface off the internet: allow it only from trusted internal networks.
- Check for compromise. Fortinet lists modified or added system files, including liblog.so, smit, webconsole, mailservice, httpd.conf and ld.so.preload, and two addresses, 79.141.169.187 and 45.129.0.192. Look for them in logs and on the appliance. CISA flags this entry for forensic triage.
- Patch as soon as Fortinet publishes 8.0.2, 7.6.7 or 7.4.9, and plan the move off 7.2.
- If a provider runs FortiMail for you, ask in writing whether the workaround is in place and whether it has checked for the indicators.
Why it matters
An email gateway sees every message an organisation sends and receives, and sits on the network edge by design. An attacker able to write files on it can plant a back door, read mail in transit or move further into the network. Edge appliances from several vendors have been the first target of attack campaigns this year, and the time between disclosure and mass exploitation is often days.
Sources
- Fortinet PSIRT: FG-IR-26-175, FortiMail path traversal (CVE-2026-104286) — 1 October 2026
- CISA Known Exploited Vulnerabilities catalogue: CVE-2026-104286, Fortinet FortiMail (added 1 October 2026) — 1 October 2026
- BleepingComputer: Fortinet warns of critical FortiMail flaw exploited in zero-day attacks — 1 October 2026
- CSIRT Italia (ACN): Fortinet, rilevato sfruttamento in rete della CVE-2026-104286 relativa a FortiMail — 2 October 2026
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
- Email Management
- Threat Intelligence
- Network Security
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.