Fortinet is warning customers that attackers are actively exploiting a critical FortiMail zero-day that allows an unauthenticated attacker to write arbitrary files to vulnerable email security appliances.
The vulnerability, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple supported FortiMail branches. Fortinet disclosed the flaw on Oct. 1 after its Product Security team identified the vulnerability internally.
The situation is particularly urgent because exploitation is already occurring and fixed FortiMail releases were not yet available when Fortinet issued its advisory. The U.S. Cybersecurity and Infrastructure Security Agency also added the vulnerability to its Known Exploited Vulnerabilities catalog on Oct. 1.
CISA gave federal civilian agencies until Oct. 4 to address the vulnerability and perform required forensic triage.
Attackers can write files without authentication
CVE-2026-104286 is a path traversal vulnerability involving improper handling of file paths and NULL characters.
According to Fortinet’s security advisory, an unauthenticated remote attacker can exploit the vulnerability using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying FortiMail system.
The vulnerability requires no user interaction or authentication, increasing the risk to FortiMail management interfaces exposed to untrusted networks.
Fortinet said the vulnerability has been reported as exploited in the wild and urged customers to apply its workaround.
The following FortiMail releases are affected:
FortiMail 8.0.0through8.0.1FortiMail 7.6.0through7.6.6FortiMail 7.4.0through7.4.8FortiMail 7.2.0through7.2.9
Fortinet said fixes are planned for upcoming FortiMail 8.0.2, 7.6.7 and 7.4.9 releases. Customers using the affected 7.2 branch are advised to move to the 7.4 branch or later.
Fortinet publishes signs of compromise
Fortinet has also provided indicators intended to help administrators determine whether their systems may already have been compromised.
Those indicators include unusual system activity involving scheduled commands, administrator events, encryption-related errors and configuration changes associated with remote archive destinations.
Some of the activity described by Fortinet could indicate an attacker configured a compromised FortiMail appliance to transfer archived information to remote infrastructure.
The indicators are significant because they give defenders evidence to hunt for beyond simply determining whether a vulnerable FortiMail version is installed.
Fortinet has not publicly disclosed when exploitation began, how many organizations have been compromised or the identity of the attackers behind the activity.
No patch available at disclosure
Until fixed releases become available, Fortinet is advising administrators to disable Identity-Based Encryption support where the feature is not required.
Organizations can also prevent internet access to the FortiMail management interface and restrict management access to trusted private networks.
Administrators should additionally review Fortinet’s published indicators of compromise rather than assuming that applying the mitigation alone rules out an earlier intrusion.
The distinction is important for an actively exploited zero-day. Systems may have been targeted before administrators became aware of the vulnerability, meaning remediation and compromise assessment are separate tasks.
CISA orders rapid federal response
CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on the same day Fortinet publicly disclosed the vulnerability.
The agency classified exploitation as active and set Oct. 4 as the remediation deadline for affected federal civilian agencies.
While CISA’s directive applies to federal civilian agencies rather than private organizations, inclusion in the KEV catalog confirms that exploitation is no longer theoretical.
The latest exploitation also follows other large-scale activity targeting Fortinet infrastructure. As BreachNews previously reported, approximately 75,000 Fortinet devices were targeted in a separate credential abuse campaign affecting organizations worldwide.
FortiMail’s position as an email security gateway also makes successful compromise particularly sensitive. The appliances can occupy a trusted position in corporate email infrastructure and may handle or interact with potentially sensitive communications and credentials.
Fortinet has not attributed the exploitation to a ransomware operation, cybercrime group or state-backed threat actor.
Organizations running affected FortiMail versions should apply Fortinet’s mitigations, restrict exposed management interfaces and review available telemetry for indicators of prior compromise while awaiting the applicable security update.











