Skip to content
TrustList
News

FortiMail flaw CVE-2026-104286 is exploited and fixes are still upcoming: disable IBE or close the management interface now

Editorial

By TrustList Editorial

Fortinet says CVE-2026-104286, an unauthenticated file-write flaw in FortiMail rated 9.8, is exploited in the wild. Fixed builds 8.0.2, 7.6.7 and 7.4.9 are listed as upcoming. Disable IBE or restrict the management interface, and check for the indicators.

About FortiMail flaw CVE-2026-104286 is exploited and fixes are still upcoming: disable IBE or close the management interface now

FortiMail flaw CVE-2026-104286 is exploited and fixes are still upcoming: disable IBE or close the management interface now

2 October 2026 — Fortinet published advisory FG-IR-26-175 on 1 October 2026 for CVE-2026-104286, a flaw in FortiMail, its email security gateway. Fortinet describes a path-traversal and NULL-byte handling weakness that "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests", and says it has been exploited in the wild. It rates the flaw 9.8 out of 10. The US Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalogue the same day and gave US federal agencies until 4 October to act. BleepingComputer reported it on 1 October and Italy's national CSIRT issued an alert on 2 October.

Affected versions and the fixes

Branch Affected Fix named by Fortinet
FortiMail 8.0 8.0.0 to 8.0.1 8.0.2 or later
FortiMail 7.6 7.6.0 to 7.6.6 7.6.7 or later
FortiMail 7.4 7.4.0 to 7.4.8 7.4.9 or later
FortiMail 7.2 7.2.0 to 7.2.9 move to 7.4 or later

When we read the advisory on 2 October, Fortinet listed these fixed builds as upcoming, and the Italian CSIRT also said no fixed release was yet available. Until the build for your branch is published, the workaround is the only protection.

What to do now

  • Disable the IBE (Identity-Based Encryption) feature from the CLI if you do not depend on it, as Fortinet's workaround describes.
  • Take the management interface off the internet: allow it only from trusted internal networks.
  • Check for compromise. Fortinet lists modified or added system files, including liblog.so, smit, webconsole, mailservice, httpd.conf and ld.so.preload, and two addresses, 79.141.169.187 and 45.129.0.192. Look for them in logs and on the appliance. CISA flags this entry for forensic triage.
  • Patch as soon as Fortinet publishes 8.0.2, 7.6.7 or 7.4.9, and plan the move off 7.2.
  • If a provider runs FortiMail for you, ask in writing whether the workaround is in place and whether it has checked for the indicators.

Why it matters

An email gateway sees every message an organisation sends and receives, and sits on the network edge by design. An attacker able to write files on it can plant a back door, read mail in transit or move further into the network. Edge appliances from several vendors have been the first target of attack campaigns this year, and the time between disclosure and mass exploitation is often days.

Sources

Categories & features