FortiMail CVE-2026-104286 is being exploited, and the fixed builds are not available yet.
What happened
Fortinet published FG-IR-26-175 on 1 October. It is a path-traversal and null-byte flaw. An unauthenticated attacker can write arbitrary files with a crafted HTTP or HTTPS request.
Fortinet rates it CVSS 9.8 and says it has been exploited. CISA added it to the Known Exploited Vulnerabilities catalog the same day. The federal due date is 4 October.
Who is affected
- FortiMail 8.0.0 through 8.0.1
- FortiMail 7.6.0 through 7.6.6
- FortiMail 7.4.0 through 7.4.8
- FortiMail 7.2.0 through 7.2.9
Fixed builds 8.0.2, 7.6.7, and 7.4.9 are listed as upcoming, not available. The 7.2 branch is told to move to 7.4 or above, which stays vulnerable until 7.4.9 ships.
What to do now
- Disable Identity-Based Encryption, or take the webmail interface off the internet, until a fixed build is actually installed.
- If that interface was reachable, assume exposure and hunt before you wait for firmware. Fortinet published attacker IPs and log strings for that check.
A file-write on a mail gateway in front of customer domains is not a routine patch ticket.
Source: Fortinet PSIRT FG-IR-26-175
Also on the blog
- Cisco SD-WAN Manager admin bypass is on the KEV list
- CISA lists two Zammad bugs that an AI-driven attack already chained to root
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.