FortiMail zero-day is exploited, and most fixes are not shipped
CVE-2026-104286, fixes not shipped

FortiMail zero-day is exploited, and most fixes are not shipped

FortiMail CVE-2026-104286 is being exploited, and the fixed builds are not available yet.

What happened

Fortinet published FG-IR-26-175 on 1 October. It is a path-traversal and null-byte flaw. An unauthenticated attacker can write arbitrary files with a crafted HTTP or HTTPS request.

Fortinet rates it CVSS 9.8 and says it has been exploited. CISA added it to the Known Exploited Vulnerabilities catalog the same day. The federal due date is 4 October.

Who is affected

  • FortiMail 8.0.0 through 8.0.1
  • FortiMail 7.6.0 through 7.6.6
  • FortiMail 7.4.0 through 7.4.8
  • FortiMail 7.2.0 through 7.2.9

Fixed builds 8.0.2, 7.6.7, and 7.4.9 are listed as upcoming, not available. The 7.2 branch is told to move to 7.4 or above, which stays vulnerable until 7.4.9 ships.

What to do now

  • Disable Identity-Based Encryption, or take the webmail interface off the internet, until a fixed build is actually installed.
  • If that interface was reachable, assume exposure and hunt before you wait for firmware. Fortinet published attacker IPs and log strings for that check.

A file-write on a mail gateway in front of customer domains is not a routine patch ticket.

Source: Fortinet PSIRT FG-IR-26-175

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

The Next Frontier:
AI-Generated Content and the Evolution of Personalized Experiences