Critical FortiMail Zero-Day Exploited in the Wild: Mitigate CVE-2026-104286 Now

Fortinet warns that critical FortiMail zero-day CVE-2026-104286 is under active attack. See affected versions, mitigations, and what to do now.

Written By
Matt Gonzales
Matt Gonzales
Oct 2, 2026
4 minute read
A FortiMail email security appliance in a server rack.

A FortiMail email security appliance in a server rack. Fortinet has warned that the critical CVE-2026-104286 vulnerability is being actively exploited. Image: Generated via OpenAI/ChatGPT

eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Fortinet is warning customers about a critical FortiMail vulnerability that attackers are already exploiting in the wild.

The flaw, tracked as CVE-2026-104286, carries a 9.8 CVSS score and can allow an unauthenticated attacker with access to the FortiMail management interface to write arbitrary files to vulnerable systems using specially crafted HTTP or HTTPS requests. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog on Oct. 1.

For organizations running FortiMail email security gateways, the combination of remote access, no authentication requirement, and confirmed exploitation makes immediate mitigation especially important while affected customers wait for applicable fixed releases.

How the FortiMail zero-day works

According to Fortinet's security advisory, CVE-2026-104286 is an improper pathname restriction (path traversal) vulnerability affecting FortiMail.

An attacker does not need an authenticated account to exploit the flaw, but does need access to the FortiMail management interface. Specially crafted HTTP or HTTPS requests sent to an accessible management interface can be used to write arbitrary files on the underlying system.

The vulnerability received a CVSS v3.1 score of 9.8 out of 10, reflecting several characteristics that make it particularly dangerous:

  • It can be exploited remotely over a network.
  • Attack complexity is rated low.
  • No privileges are required.
  • No user interaction is required.
  • Successful exploitation can have a high impact on confidentiality, integrity, and availability.

Most importantly, this is not a theoretical risk. Fortinet says CVE-2026-104286 has been exploited in the wild, and CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.

CISA's assessment also classifies exploitation as active, the attack as automatable, and the potential technical impact as total.

The disclosure follows other cases this year in which attackers have targeted Fortinet security infrastructure. In April, eSecurityPlanet reported on a critical FortiClient EMS vulnerability that was being actively exploited, allowing unauthenticated attackers to bypass API protections.

Advertisement

Which FortiMail versions are affected?

Fortinet's published information indicates that multiple FortiMail branches are affected, although administrators should be aware that the company's published CVE data contains discrepancies in the exact affected-version ranges.

The Canadian Centre for Cyber Security's Oct. 1 advisory provides the following remediation targets:

  • FortiMail 8.0: Upgrade to 8.0.2 or later when available.
  • FortiMail 7.6: Upgrade to 7.6.7 or later when available.
  • FortiMail 7.4: Upgrade to 7.4.9 or later when available.
  • FortiMail 7.2: Fortinet recommends migrating to the 7.4 branch or later. However, administrators should not assume that moving to any 7.4 release resolves CVE-2026-104286, as FortiMail 7.4 versions prior to the upcoming 7.4.9 release are also affected. Until an applicable fixed release is available, organizations should apply Fortinet's interim mitigations.

Fortinet's structured CVE information also references the FortiMail 7.0 branch, while other published descriptions differ slightly on the upper bounds of affected 7.4 and 7.6 releases. Administrators should therefore consult Fortinet's latest advisory for their specific branch rather than relying solely on a static list of versions.

At the time of disclosure, applicable fixed releases were listed as upcoming, making Fortinet's interim mitigations particularly important.

Fortinet products have repeatedly drawn attacker attention because compromising security infrastructure can give threat actors a valuable foothold. Earlier this year, another Fortinet SSO vulnerability was exploited to gain administrative access to affected systems.

What security teams should do now

Organizations using FortiMail should first determine whether any deployed appliances are running an affected release and prioritize systems with management interfaces accessible from the internet.

While waiting for applicable fixed releases, Fortinet recommends interim mitigations. Depending on the organization's configuration, these include disabling IBE support or preventing internet access to the FortiMail management interface and restricting management access to trusted private networks.

Security teams should also:

  • Apply Fortinet's recommended mitigations immediately to affected FortiMail deployments.
  • Install the appropriate fixed FortiMail release when it becomes available for the affected branch.
  • Restrict management-interface access to trusted networks and administrators.
  • Review HTTP and HTTPS activity for suspicious requests targeting the FortiMail management interface.
  • Inspect affected appliances for signs of unauthorized file creation or modification, particularly if their management interfaces were accessible over the internet before mitigation.
  • Investigate potentially exposed systems for compromise. Because exploitation has already been confirmed, applying a mitigation or update does not establish that an appliance was not compromised beforehand.
Advertisement

CISA's decision to add CVE-2026-104286 to the KEV catalog underscores the urgency. Federal civilian agencies are required to remediate known exploited vulnerabilities according to CISA's deadlines, but organizations outside the federal government can also use the catalog to prioritize vulnerabilities that attackers are demonstrably using.

Fortinet vulnerabilities have been a recurring concern for defenders. eSecurityPlanet previously covered active exploitation of a FortiSIEM remote code execution flaw, another example of attackers targeting security products positioned deep inside enterprise environments.

What the FortiMail flaw means for defenders

CVE-2026-104286 is especially concerning because FortiMail is itself a security product designed to sit in the path of enterprise email traffic. A vulnerable security appliance can become another attack surface rather than the barrier organizations expect it to be.

For security administrators, the immediate priority is to identify affected FortiMail deployments, restrict access to exposed management interfaces, and apply Fortinet's interim mitigations. Teams should also investigate systems whose management interfaces were exposed before those protections were implemented.

Once the appropriate fixed release becomes available, organizations should upgrade promptly and continue checking previously exposed appliances for evidence of compromise.

For more on securing exposed Fortinet infrastructure, read how a FortiOS authentication bypass can expose VPN and SSO deployments.


Matt Gonzales

Matt Gonzales is the Managing Editor of Cybersecurity for eSecurity Planet. An award-winning journalist and editor, Matt brings over a decade of expertise across diverse fields, including technology, cybersecurity, and military acquisition. He combines his editorial experience with a keen eye for industry trends, ensuring readers stay informed about the latest developments in cybersecurity.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.