Critical FortiMail Zero-Day Exploited With No Patch Yet

Fortinet confirmed active exploitation of a critical FortiMail flaw with no fix shipped for most versions, and CISA added it to its exploited list.
Table of Contents
    Add a header to begin generating the table of contents

    Fortinet has confirmed that attackers are actively exploiting a maximum-severity zero-day flaw in its FortiMail secure email gateway, and the Cybersecurity and Infrastructure Security Agency has added the vulnerability to its Known Exploited Vulnerabilities catalog — while fixed firmware remains unavailable for most affected versions.

    CVE-2026-104286 Lets Unauthenticated Attackers Write Arbitrary Files

    Fortinet disclosed the flaw, tracked as CVE-2026-104286 and rated a maximum 9.8 on the CVSS scale, as affecting FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The vulnerability combines a path traversal weakness with improper handling of NULL byte characters, letting an unauthenticated attacker send crafted HTTP or HTTPS requests that write arbitrary files to the underlying operating system.

    Fortinet stated that exploitation can lead to arbitrary code or command execution on affected appliances. The company said it “has been reported to be exploited in the wild” against FortiMail management interfaces, though it has not disclosed which threat actor is behind the activity or how attackers are reaching exposed instances.

    Fortinet’s Own Security Team, Not an Outside Researcher, Caught the Bug

    Unlike many high-profile zero-days that reach vendors through external bug bounty programs or incident-response engagements, CVE-2026-104286 was discovered internally by Fortinet’s Product Security team, credited to researcher Gwendal Guegniaud. Fortinet disclosed the flaw and confirmed active exploitation on October 1, and CISA added it to the KEV catalog the following day.

    That sequence — internal discovery followed almost immediately by a confirmation of in-the-wild attacks — suggests Fortinet’s security team identified the flaw only after exploitation was already underway, rather than getting ahead of attackers with a quiet, pre-exploitation fix.

    No Patched Firmware Ships for Most Affected FortiMail Branches

    Fortinet has not yet released fixed firmware for the majority of affected versions. Patched releases — 7.4.9, 7.6.7, and 8.0.2 — are in development, but the company has not provided a release timeline for any of them. FortiMail 7.2 users have one option unavailable to administrators on other branches: they can upgrade directly to the 7.4 line or later as an interim fix, since 7.4.9 is not yet shipped but a newer 7.4.x build may still close the gap.

    Interim Workarounds Are the Only Option for Most Administrators

    With no patch available, Fortinet is directing customers toward two workarounds: disabling the Identity-Based Encryption feature on FortiMail, or restricting access to the appliance’s web-based management interface to trusted source addresses only. Neither workaround removes the underlying flaw — they reduce the attack surface available to an unauthenticated attacker by limiting what the vulnerable management interface can be reached from.

    Fortinet said it is coordinating disclosure with CISA and other government agencies, and federal guidance is expected to follow the KEV addition. For organizations that cannot immediately lock down management-plane access, the absence of a shipped fix leaves genuinely limited options beyond monitoring for signs of compromise.

    Why an Unpatched, Actively Exploited Email Gateway Flaw Is Different

    Secure email gateways occupy an unusual position in enterprise networks: they are deliberately internet-facing, process untrusted content from every external sender by design, and typically hold elevated trust relationships with internal mail and directory systems. A flaw that lets an attacker write arbitrary files to that appliance without authentication effectively hands over a foothold inside the perimeter — not through a phishing email that slips past the gateway, but through the gateway itself.

    What separates this disclosure from a routine advisory is the combination of three factors rarely stacked together: a 9.8 CVSS score, confirmed active exploitation, and no available patch across most supported branches. Security teams typically treat vendor disclosures as a signal to schedule patching; here, patching is not yet an option for most deployments, which shifts the entire response to interim mitigation. Administrators running FortiMail should treat any internet-facing management interface as presumptively exposed until Fortinet ships 7.4.9, 7.6.7, or 8.0.2, regardless of how quickly their change-management process would normally allow a fix to be applied.

    What the KEV Listing Means for Organizations Beyond Federal Agencies

    CISA’s Known Exploited Vulnerabilities catalog carries binding remediation requirements for federal civilian agencies, but its practical influence extends well beyond government networks. Security teams across industries routinely use KEV additions as a prioritization signal, since inclusion means CISA has independently verified that a flaw is already being weaponized rather than merely theoretical. For CVE-2026-104286, that verification arrived the day after Fortinet’s own disclosure, compressing the usual gap between “a vendor says this is serious” and “a government agency confirms attackers are already using it.”

    That compressed timeline leaves little room for organizations to treat this as a lower-priority item on a patch backlog. Perimeter security appliances such as FortiMail have repeatedly drawn attacker interest precisely because they combine internet exposure with privileged access to internal systems, and a confirmed KEV listing on a flaw with no shipped fix is, in effect, a direct instruction to act on workarounds immediately rather than wait for a scheduled firmware update.

    Related Posts