Fortinet FortiMail Has a Critical Zero-Day Being Exploited and No Patch Yet
A vulnerability scored 9.8 out of 10 in Fortinet FortiMail lets attackers write files to affected servers without logging in. Fixes are not out yet. US federal agencies had until 4 October 2026 to apply workarounds.

Key points
- CVE-2026-104286 carries a CVSS score of 9.8 out of 10 and is already being exploited against unpatched Fortinet FortiMail servers.
- The flaw lets an attacker without credentials write any file they choose to the underlying server, potentially taking full control.
- CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue on 1 October 2026, giving US federal agencies three days to act under binding operational directive BOD 26-04.
- Fortinet has confirmed fixes are coming but has not given a release date; a workaround is available now.
- Four separate version branches of FortiMail are affected, from 7.2.0 through 8.0.1.
Fortinet's FortiMail, an email security gateway used to filter spam and block malicious attachments, contains a flaw attackers are already exploiting in real-world attacks. No patch exists at the time of writing.
The vulnerability, CVE-2026-104286, is a path traversal bug combined with improper handling of NULL bytes. Path traversal means software fails to stop an outside request from reaching files it was never meant to touch; a NULL byte is a special character that can confuse software into misreading a filename. Together, they let an attacker craft a malicious HTTP or HTTPS request and plant files anywhere on the machine running FortiMail, without supplying a valid login. Fortinet discovered the bug internally, according to the company's own advisory.
Which versions are affected?
Four FortiMail version branches are vulnerable. Every organisation running any of these should treat the situation as urgent.
| Version branch | Affected releases | Fix target |
|---|---|---|
| FortiMail 8.0 | 8.0.0 to 8.0.1 | Upgrade to 8.0.2 (upcoming) |
| FortiMail 7.6 | 7.6.0 to 7.6.6 | Upgrade to 7.6.7 (upcoming) |
| FortiMail 7.4 | 7.4.0 to 7.4.8 | Upgrade to 7.4.9 (upcoming) |
| FortiMail 7.2 | 7.2.0 to 7.2.9 | Move to branch 7.4 or above |
Fortinet has not given a release date for any of these fixes.
What can organisations do right now?
The Fortinet advisory lists three workarounds. First, disable the IBE feature (Identity-Based Encryption, a method FortiMail uses to send encrypted email to recipients without their own certificates) via the graphical interface under Encryption, then IBE, then setting IBE Service to off. Second, block the FortiMail web interface from reaching the public internet, or restrict it to trusted internal addresses. Third, if a web application firewall sits in front of FortiMail, configure it to block POST requests to the path /ibe that contain the characters '../'. Fortinet also published indicators of compromise to help security teams check whether intrusions have already occurred.
Neither Fortinet nor CISA has described who is behind the observed attacks or named specific targets, as SecurityWeek first reported. This pattern of a critical pre-authentication file-write with no patch date and a three-day federal deadline is one we've tracked closely: our coverage of F5's BIG-IP zero-day on 28 September ran under almost identical circumstances just days ago.
The uncomfortable reality: this is actively exploited, pre-authentication file-write on email security infrastructure, and the vendor is asking customers to hold on a workaround with no confirmed patch date. Apply the IBE disable and the network restriction today, then watch Fortinet's advisory page for the moment 8.0.2, 7.6.7, and 7.4.9 ship.



