Critical FortiMail Vulnerability
A critical security vulnerability affecting Fortinet's FortiMail email security platform is currently being exploited by attackers. The vulnerability, identified as CVE-2026-104286, was disclosed by Fortinet on October 1, 2026, and cybersecurity authorities have now warned organizations to take immediate action. Help Net Security+1
The flaw has received a CVSS score of 9.8 out of 10, making it a critical vulnerability. More importantly, Fortinet has confirmed that the vulnerability is already being exploited in real-world attacks.
A Vulnerability That Requires No Authentication
CVE-2026-104286 affects the FortiMail management interface. It combines a path traversal vulnerability with improper handling of NULL characters.
In practical terms, an attacker does not need valid credentials to exploit the vulnerability. By sending specially crafted HTTP or HTTPS requests, an attacker can potentially write arbitrary files to the underlying system.
This can become particularly serious if an attacker manages to place files in sensitive locations. According to Fortinet's advisory, successful exploitation could ultimately lead to unauthorized code or command execution on the affected device. The Hacker News+1
Which Versions Are Affected?
The vulnerability affects several FortiMail branches.
FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6 and 8.0.0 through 8.0.1 are affected.
Fortinet has announced fixes for newer releases, including versions 7.4.9, 7.6.7 and 8.0.2. At the time of the initial disclosure, these updates were still listed as upcoming. Organizations using the affected 7.2 branch are advised to move to the 7.4 branch or later. Help Net Security+1
Attackers Are Already Exploiting the Flaw
The biggest concern is that this is not simply a theoretical vulnerability.
Fortinet has confirmed that CVE-2026-104286 is being exploited in the wild. However, the company has not publicly disclosed how many FortiMail appliances have been compromised or who is responsible for the attacks. SOCRadar® Cyber Intelligence Inc.+1
The U.S. Cybersecurity and Infrastructure Security Agency has also added the vulnerability to its Known Exploited Vulnerabilities catalog. U.S. federal civilian agencies were given until October 4 to address the issue. Help Net Security+1
The French CERT-FR has also published an alert on October 2, classifying the vulnerability as capable of allowing remote arbitrary code execution and confirming Fortinet's statement that it is actively exploited. CERT-FR
What Should Organizations Do?
Because security patches were not yet available for every affected branch when the vulnerability was disclosed, Fortinet recommended temporary measures.
Organizations can disable FortiMail's Identity-Based Encryption feature, known as IBE. Another option is to restrict access to the FortiMail management interface so that it cannot be reached directly from the public internet.
Administrators should also review Fortinet's indicators of compromise and investigate their systems for signs of unauthorized activity. Help Net Security+1
These measures are particularly important for organizations that expose their FortiMail management interface to the internet.
Why This Vulnerability Matters
FortiMail is designed to protect organizations' email infrastructure, which makes a vulnerability in the platform especially concerning.
Email systems are often connected to sensitive business information and can provide attackers with access to credentials, communications and other internal resources. A successful compromise of an email security appliance could therefore become the starting point for additional attacks against an organization.
The combination of a critical severity score, no authentication requirement and active exploitation makes CVE-2026-104286 an important vulnerability for organizations using FortiMail to monitor closely.
For now, Fortinet has not publicly identified the attackers behind the exploitation. What is clear is that the vulnerability is already being used in real-world attacks, meaning organizations running affected versions should not wait for an incident before reviewing their exposure.
The FortiMail case is another reminder that vulnerabilities affecting security appliances can be particularly dangerous. These systems are designed to protect an organization's infrastructure, but when they themselves become compromised, they can potentially provide attackers with a valuable position inside the network.