Security News

Critical FortiMail Flaw Under Active Attack, Patches Still Pending for Some Versions

The Register · 2 Oct 2026
Key Takeaway If your business uses FortiMail, immediately restrict the management interface from internet access, check Fortinet's indicators of compromise, and apply patches as soon as they become available for your version.

Fortinet has issued an urgent warning after attackers were found exploiting a severe flaw in its FortiMail email security platform. The vulnerability, tracked as CVE-2026-104286, scores 9.8 out of 10 for severity and allows an attacker to write files to a vulnerable system without needing to log in. By combining path traversal with improper handling of certain characters, attackers can send crafted web requests that place files in locations enabling them to run code or commands on the device.

The flaw affects multiple FortiMail versions, including releases in the 8.0, 7.6, 7.4 and 7.2 branches. Fortinet has not disclosed when exploitation began, who is responsible, or how many organisations have been affected, but has published indicators of compromise, including suspicious files, configuration changes and attacker IP addresses. The US Cybersecurity and Infrastructure Security Agency has added the flaw to its Known Exploited Vulnerabilities catalog, directing federal agencies to investigate and apply mitigations by October 4.

Fixes for several affected versions are still listed as upcoming, leaving some customers dependent on temporary workarounds. Fortinet recommends disabling Identity Based Encryption where it isn't needed, and restricting access to the FortiMail management interface so it cannot be reached from the internet. Importantly, applying a workaround will not remove any malicious files or persistence mechanisms already planted by attackers, so checking for compromise is essential.

Fortinet FortiMail zero-day vulnerability email security CISA
Primary source cisa.gov ->

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.