Fortinet and CISA warned on 1 October 2026 that CVE-2026-104286 is being exploited. It is a critical path-traversal flaw, CVSS 9.8, that lets an unauthenticated attacker write arbitrary files on a FortiMail system with crafted HTTP or HTTPS requests. Fixed releases were not available when the advisory went out.
What happened
Fortinet PSIRT advisory FG-IR-26-175 describes a path traversal plus improper NULL-byte handling. The company says the bug can lead to unauthorized code or command execution, marks it as exploited, and published indicators of compromise. CISA put it on the KEV catalog the same day, with a federal due date of 4 October and forensic triage required.
Public reporting places the vulnerable path in the Identity-Based Encryption feature, not in ordinary SMTP. The management interface has to be reachable for the request to land.
Who is affected
- FortiMail 8.0.0 through 8.0.1. Fix is upcoming 8.0.2 or above.
- FortiMail 7.6.0 through 7.6.6. Fix is upcoming 7.6.7 or above.
- FortiMail 7.4.0 through 7.4.8. Fix is upcoming 7.4.9 or above.
- FortiMail 7.2.0 through 7.2.9. Fortinet points this branch to 7.4 or above.
What to do now
Disable IBE or take the management interface off the internet, then hunt the Fortinet IoCs before you trust the box. The CLI workaround is config system encryption ibe, then set status disable. Disabling IBE stops the secure-message portal until you turn it back on. Neither workaround removes an attacker who is already on the appliance. Watch for unexpected files under data and bin paths, a malicious ld.so.preload, and a changed httpd.conf, as described in the vendor write-up.
Source: SecurityWeek, Exploited Fortinet FortiMail zero-day calls for urgent action. Vendor advisory: FG-IR-26-175.
Also on the blog
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- GitLab AI Gateway sandbox escape is a 9.9, patches are out
- CVE-2026-102489: Zammad zero-day chain, KEV due 5 October
- Warlock is still entering through on-prem SharePoint, including water and telecom
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.