At a glance:
-
Fortinet disclosed active exploitation of CVE-2026-104286 on October 1, 2026. At disclosure, patches were not available for affected FortiMail 7.4, 7.6, and 8.0 deployments, leaving organizations reliant on mitigations while fixed releases remain pending.
-
CVE-2026-104286 allows an unauthenticated adversary to write files to a vulnerable FortiMail system through crafted web requests. Fortinet states that these file writes may lead to unauthorized code or command execution.
-
The highest-risk scenario is internet-exposed FortiMail systems where the vulnerable IBE functionality is accessible. Fortinet has published indicators of compromise to help identify affected systems while organizations prepare to deploy fixes as they become available.
Threat summary
On October 1, 2026, Fortinet reported on active exploitation of a zero-day in Fortinet FortiMail and published indicators of compromise and mitigation guidance. The same day, CISA added the vulnerability to the KEV catalog.
At the time of disclosure, patches were not available for affected FortiMail 7.4, 7.6, and 8.0 deployments. Organizations running FortiMail 7.2.x have a patch available and can address the vulnerability by upgrading to the FortiMail 7.4 branch or later.
FortiMail is an email security gateway that sits between external mail systems and internal users. It performs functions such as spam filtering, malware detection, message inspection, encryption, and policy enforcement. Because the platform processes and routes organizational email, it commonly occupies a trusted position within enterprise environments and often has visibility into both inbound and outbound communications.
The flaw, tracked as CVE-2026-104286, is caused by a path traversal weakness combined with improper handling of NULL byte characters. The vulnerable functionality is exposed through FortiMail's Identity-Based Encryption (IBE) service in the FortiMail management interface, specifically a web endpoint used to process requests to /ibe. These components process administrative web requests and manage encrypted email services.
Under normal operation, FortiMail restricts file writes to specific directories on the appliance. The flaw allows an unauthenticated adversary to send crafted HTTP or HTTPS requests that trick FortiMail into saving files in locations outside the directories normally controlled by the application. This gives the adversary the ability to place arbitrary files on the underlying operating system. These file writes may be used to execute unauthorized code or commands on the appliance.
Exploitation is remote, requires no valid credentials, and does not require user interaction. CVE-2026-104286 was rated with a Common Vulnerability Scoring System (CVSS) score of 9.8.
Fortinet released indicators of compromise that include added and modified binaries and configuration files found on compromised systems.
Analysis
Organizations that make the FortiMail web management application accessible from the internet face the highest exposure. The vulnerability can be reached over the network without a valid account, making internet-facing systems the most likely targets.
Email security gateways have a long history of attracting attention from threat actors because they occupy a trusted position in the flow of corporate communications. A FortiMail appliance often has visibility into inbound and outbound email, access to security policies, and connections to other parts of the messaging environment. Compromising a system in that position can provide far more value than compromising an individual workstation.
The indicators of compromise released by Fortinet include modified system files and additional binaries, showing that observed intrusions involved changes to the appliance after access was obtained.
The broader impact depends on how FortiMail is deployed. In many environments, the platform has visibility into email traffic, message quarantine functions, encryption services, and administrative workflows. If an adversary is able to execute code on the appliance, that access could be used to view email-related data, alter mail-handling behavior, capture credentials used to administer the system, or maintain access to the appliance over time. These outcomes depend on the environment and have not been publicly reported as part of the observed exploitation activity.
For operational teams, the most important detail is that active exploitation was reported before fixes became widely available. Any exposed FortiMail appliance running an affected version warrants immediate review for the published indicators of compromise and any unexpected administrative or system-level changes.
Mitigations
-
To establish exposure and remediation priorities, review all FortiMail deployments and identify systems running versions:
-
7.2.0 through 7.2.9
-
7.4.0 through 7.4.8
-
7.6.0 through 7.6.6
-
8.0.0 through 8.0.1
-
Deploy Fortinet's fixed releases when available. Fortinet has identified FortiMail 7.4.9, 7.6.7, and 8.0.2 as the releases that will address CVE-2026-104286, allowing temporary mitigations to be replaced with a permanent fix. Organizations running FortiMail 7.2.x can address the vulnerability by upgrading to the FortiMail 7.4 branch or later.
-
Disable IBE functionality where operationally feasible to remove the vulnerable attack path exposed through the /ibe endpoint.
-
Limit access to the FortiMail web management application to trusted private networks to reduce exposure to unauthenticated exploitation attempts originating from the internet.
-
Investigate any FortiMail appliance that matches Fortinet's published indicators of compromise as a potential security incident. Review when the files were created or modified, determine whether unauthorized administrative activity occurred, identify any accounts that may have been accessed, and examine connected email, authentication, and network infrastructure for evidence of follow-on activity. Appliances showing signs of compromise may require containment, forensic review, and rebuilding from a trusted source.
-
Monitor FortiMail administrative activity, configuration changes, and network connections for signs of follow-on activity originating from a compromised appliance. Correlating FortiMail events with authentication, email, and network telemetry can help identify broader intrusion activity.