The news
Fortinet (FTNT) warned on October 1, 2026, that a critical flaw in FortiMail, its email security gateway, is being exploited in the wild. The bug, CVE-2026-104286, lets an unauthenticated attacker write arbitrary files on the appliance, according to Fortinet's advisory.
The advisory, FG-IR-26-175, describes a path traversal weakness combined with improper handling of null bytes. Path traversal means an attacker can trick software into reaching files outside the folder it is supposed to stay in. Fortinet says the flaw can be triggered with crafted HTTP or HTTPS requests, and it rates it 9.8 out of 10 on the CVSS v3.1 severity scale.
The affected releases are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9. Fortinet's advisory, updated on October 5 with a solution update, tells customers to move to 8.0.2, 7.6.7 or 7.4.9 or above, and tells 7.2 customers to move to the 7.4 branch or later. When The Register and The Hacker News reported the flaw on October 2, those releases were listed as upcoming.
The US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on October 1, The Hacker News reported, and set an October 4 deadline for federal civilian agencies to act. Fortinet credited Gwendal Guégniaud of its own Product Security team with finding the issue.
Fortinet's suggested workarounds include disabling the Identity Based Encryption (IBE) feature, a FortiMail function tied to encrypted message delivery, and limiting webmail access to trusted networks. The advisory also suggests web application firewall rules that block POST requests to the IBE path containing directory traversal strings. It lists two IP addresses linked to the attacks, 79.141.169.187 and 45.129.0.192, along with log entries to look for, such as failed IBE decryption errors and suspicious archive account settings.
The numbers
- CVSS v3.1 severity score
- 9.8 (Critical)
- FortiMail release branches affected
- 4 (8.0, 7.6, 7.4, 7.2)
- CISA deadline for federal agencies
- October 4, 2026
- Attacker IP addresses listed by Fortinet
- 2
Why CEOs should care
An email gateway sits in front of every message a company sends and receives, so a file-write flaw on that box is a foothold in the system meant to filter phishing and malware. CISOs should confirm right away which FortiMail units are running an affected release, whether the IBE feature is switched on, and whether the web interface can be reached from the internet. If an upgrade must wait, Fortinet's workarounds are the stopgap.
Patching alone does not answer whether a device was already hit. Because exploitation was underway before fixed releases were listed, security teams should search logs for the IP addresses and log entries Fortinet published, and check for planted files and configuration changes, steps Fortinet advised according to The Register. An appliance that shows signs of compromise should be treated as an incident, with mail flow and admin credentials reviewed.
For boards and CFOs, the useful question is how quickly edge devices like this one get patched when a vendor says a flaw is exploited. CISA gave federal agencies three days. Ask the security team what the company's own target is for exploited flaws on internet-facing gear, how often it is met, and whether managed service providers that run your email security are held to the same clock.
The bigger picture
Network and security appliances that face the internet have become a favored target because they are exposed by design and often run with high privileges. This FortiMail flaw is one of several critical, actively exploited bugs in edge and gateway products disclosed by vendors in recent weeks, which keeps patch speed for these devices on the risk agenda.
For buyers, the episode is also a reminder to look at how a vendor handles disclosure. Fortinet found this flaw through its own product security team, published workarounds and attack indicators in its advisory, and listed fixed releases in an October 5 update. Those are the practical signals procurement and security teams can compare across vendors when renewing contracts for gateway and firewall products.
What’s next
Fortinet's advisory was updated on October 5 and may change again as the investigation continues. Watch for further indicators of compromise from Fortinet, any follow-up guidance from CISA, and reports from incident response firms on who was targeted and what attackers did after gaining access.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








