FortiMail zero-day is being exploited as some fixes remain pending

Fortinet has warned that a critical FortiMail vulnerability is being exploited in the wild.

The flaw is CVE-2026-104286. Fortinet rates it critical at CVSS 9.8 and describes it as a path traversal issue combined with improper handling of null bytes in FortiMail’s GUI. The vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system using crafted HTTP or HTTPS requests.

CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1, 2026. The U.S. agency set an October 4, 2026 due date for federal civilian agencies to perform forensic triage and apply mitigations under BOD 26-04 guidance. In Canada, the Canadian Centre for Cyber Security issued advisory AV26-989 the same day and updated it on October 2.

The affected FortiMail versions

Fortinet’s public guidance lists these FortiMail release ranges as affected:

  • FortiMail 8.0.0 through 8.0.1
  • FortiMail 7.6.0 through 7.6.6
  • FortiMail 7.4.0 through 7.4.8
  • FortiMail 7.2.0 through 7.2.9

The CVSS vector describes the issue as network-accessible, low complexity, requiring no privileges and no user interaction. That combination is why the flaw is being treated as an immediate exposure problem rather than a routine maintenance item.

Public advisories and reporting connect the risk to FortiMail management access and FortiMail’s Identity Based Encryption feature. NCSC-NL described affected deployments as FortiMail systems in the listed ranges where IBE is enabled. Fortinet’s own mitigation guidance also centers on disabling IBE or preventing internet access to the management interface.

Patch timing is the difficult part

Fortinet’s solution guidance names FortiMail 8.0.2, 7.6.7 and 7.4.9 as the fixed targets, and says 7.2 deployments should move to 7.4 or later. Several same-day reports, including BleepingComputer and Help Net Security, reported that the 8.0, 7.6 and 7.4 fixed builds had not been released when the advisory was covered.

The public picture was not perfectly uniform by Friday morning. Canada’s Cyber Centre lists affected branches as versions prior to 8.0.2, 7.6.7 and 7.4.9, while NCSC-NL says Fortinet has released security updates. The practical consequence is that fixed-build availability has to be checked directly in Fortinet’s support portal for the deployed branch.

The 7.2 guidance needs particular care. Public guidance does not name a fixed 7.2 build. It points 7.2 users to 7.4 or above, while 7.4.0 through 7.4.8 are also in the affected range. A move from 7.2 should therefore land on a fixed 7.4 build or a later unaffected branch, not merely any 7.4 release.

Fortinet’s workarounds

Where no fixed build has been installed, Fortinet’s published workaround is to disable IBE feature support using the FortiMail CLI:

config system encryption ibe  
set status disable  
end

Fortinet also advises administrators to disable internet access to the FortiMail management interface or restrict that access to trusted private networks.

Those controls reduce exposure, but they do not prove that an appliance was not already attacked.

Compromise checks matter as much as patch planning

Fortinet published indicators of compromise tied to the attacks. Reported examples include added or modified files such as /data/lib/liblog.so, /data/etc/ld.so.preload, /data/bin/webconsole, /data/bin/mailservice, /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz.

Fortinet also listed 79[.]141.169.187 and 45[.]129.0.192 as IP addresses associated with the attacks. One sample log event described an archive account named archive234 configured with remote IP 79.141.169.187 and remote directory /uploads. BleepingComputer noted that this could indicate archived data was configured to leave the appliance, but Fortinet has not said how many systems were compromised or who is behind the activity.

CISA’s KEV listing confirms evidence of exploitation. It is not a victim count, and it does not identify ransomware use. The KEV record lists known ransomware campaign use as unknown.

What organizations should do now

Email security gateways sit in the path of business mail and may also handle archiving or encryption workflows. Affected FortiMail systems that exposed the management interface or IBE to untrusted networks should be treated as possibly targeted pending compromise assessment.

  • Identify FortiMail deployments and confirm the exact version and branch.
  • Check whether IBE is enabled and whether the management interface is reachable from untrusted networks.
  • Install the fixed build for the deployed branch when it is available through Fortinet’s official channel.
  • Apply Fortinet’s workaround by disabling IBE where appropriate, or remove public management access and restrict it to trusted private networks.
  • Search for Fortinet’s published indicators of compromise, including suspicious files, IP addresses, archive accounts and log patterns. Review outbound connections.
  • Treat matching indicators as an incident, not just a vulnerability-management task.
  • Monitor Fortinet PSIRT and national cyber advisories for updates, because branch guidance and build availability can change quickly.

Affected internet-reachable FortiMail deployments warrant immediate containment and evidence preservation while patch status is verified.

Get new small business insights by email

Practical ideas and useful articles to help you make better business decisions.

HelperX Bot

Not sure what to read next?

I can suggest related Tech Help Canada articles based on the topic you’re reading now.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us

Leave a Comment

Tweet
Share
Share
Pin
WhatsApp
Reddit
Email