Fortinet confirms FortiMail zero-day is under active attack with no patch available

Fortinet has confirmed that attackers are actively exploiting a critical zero-day vulnerability in FortiMail, its enterprise email security platform, and no patch is available yet. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and allows unauthenticated remote attackers to write arbitrary files anywhere on the underlying server by sending a crafted HTTP or HTTPS request.
The vulnerability combines a path traversal weakness with improper NULL byte handling. Because no authentication is required and the attack travels over standard web traffic, it is trivial for an adversary to attempt — and forensic evidence already shows that two attacker-controlled IP addresses (79.141.169.187 and 45.129.0.192) have been seen exploiting it in the wild, leaving modified system files and malicious binaries behind.
Affected versions
CVE-2026-104286 affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The flaw was discovered and reported internally by Gwendal Guégniaud of Fortinet’s Product Security team.
No patch — mitigate now
Fortinet has not yet released fixed builds. The recommended mitigations are to either disable the IBE (Identity Based Encryption) feature via the CLI, or to restrict FortiMail’s management interface to trusted private networks only. Organizations that cannot apply either workaround should treat any internet-exposed FortiMail instance as potentially compromised and investigate accordingly.
The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on October 1, 2026, giving federal civilian agencies until October 4 to act. That deadline has now passed, and the flaw remains unpatched — meaning the window for attacker access across government and enterprise deployments may already be wide open.
Why email gateways are high-value targets
FortiMail sits at the perimeter of corporate networks, processing every inbound and outbound email. A foothold on the email gateway gives attackers an ideal position to intercept communications, harvest credentials from phishing links before they are blocked, and pivot into the internal network. The arbitrary file-write primitive made possible by CVE-2026-104286 can lead directly to full system compromise if an attacker writes a web shell or modifies a startup script.
As first reported by The Hacker News, two attacker IPs and file-system indicators of compromise have been identified. Organizations running FortiMail should apply Fortinet’s workarounds immediately and audit recently modified files on affected systems while awaiting an official patch.
Originally reported by The Hacker News. Read the original article for additional details.
View original source