Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

FortiMail zero-day rated 9.8 under active attack lets hackers write files with no login

Fortinet says CVE-2026-104286 lets unauthenticated attackers write arbitrary files on FortiMail appliances, and CISA has added it to its exploited-flaws list.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Fortinet says CVE-2026-104286, rated 9.8, lets unauthenticated attackers write arbitrary files on FortiMail and is exploited in the wild.
  • 2CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1 and gave federal agencies until October 4.
  • 3Fortinet's advisory lists fixed versions and workarounds, including disabling the IBE feature and limiting web access to trusted networks.

The news

Fortinet (FTNT) warned on October 1, 2026, that a critical flaw in FortiMail, its email security gateway, is being exploited in the wild. The bug, CVE-2026-104286, lets an unauthenticated attacker write arbitrary files on the appliance, according to Fortinet's advisory.

The advisory, FG-IR-26-175, describes a path traversal weakness combined with improper handling of null bytes. Path traversal means an attacker can trick software into reaching files outside the folder it is supposed to stay in. Fortinet says the flaw can be triggered with crafted HTTP or HTTPS requests, and it rates it 9.8 out of 10 on the CVSS v3.1 severity scale.

The affected releases are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9. Fortinet's advisory, updated on October 5 with a solution update, tells customers to move to 8.0.2, 7.6.7 or 7.4.9 or above, and tells 7.2 customers to move to the 7.4 branch or later. When The Register and The Hacker News reported the flaw on October 2, those releases were listed as upcoming.

The US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog on October 1, The Hacker News reported, and set an October 4 deadline for federal civilian agencies to act. Fortinet credited Gwendal Guégniaud of its own Product Security team with finding the issue.

Fortinet's suggested workarounds include disabling the Identity Based Encryption (IBE) feature, a FortiMail function tied to encrypted message delivery, and limiting webmail access to trusted networks. The advisory also suggests web application firewall rules that block POST requests to the IBE path containing directory traversal strings. It lists two IP addresses linked to the attacks, 79.141.169.187 and 45.129.0.192, along with log entries to look for, such as failed IBE decryption errors and suspicious archive account settings.

The numbers

CVSS v3.1 severity score
9.8 (Critical)
FortiMail release branches affected
4 (8.0, 7.6, 7.4, 7.2)
CISA deadline for federal agencies
October 4, 2026
Attacker IP addresses listed by Fortinet
2

Why CEOs should care

An email gateway sits in front of every message a company sends and receives, so a file-write flaw on that box is a foothold in the system meant to filter phishing and malware. CISOs should confirm right away which FortiMail units are running an affected release, whether the IBE feature is switched on, and whether the web interface can be reached from the internet. If an upgrade must wait, Fortinet's workarounds are the stopgap.

Patching alone does not answer whether a device was already hit. Because exploitation was underway before fixed releases were listed, security teams should search logs for the IP addresses and log entries Fortinet published, and check for planted files and configuration changes, steps Fortinet advised according to The Register. An appliance that shows signs of compromise should be treated as an incident, with mail flow and admin credentials reviewed.

For boards and CFOs, the useful question is how quickly edge devices like this one get patched when a vendor says a flaw is exploited. CISA gave federal agencies three days. Ask the security team what the company's own target is for exploited flaws on internet-facing gear, how often it is met, and whether managed service providers that run your email security are held to the same clock.

The bigger picture

Network and security appliances that face the internet have become a favored target because they are exposed by design and often run with high privileges. This FortiMail flaw is one of several critical, actively exploited bugs in edge and gateway products disclosed by vendors in recent weeks, which keeps patch speed for these devices on the risk agenda.

For buyers, the episode is also a reminder to look at how a vendor handles disclosure. Fortinet found this flaw through its own product security team, published workarounds and attack indicators in its advisory, and listed fixed releases in an October 5 update. Those are the practical signals procurement and security teams can compare across vendors when renewing contracts for gateway and firewall products.

What’s next

Fortinet's advisory was updated on October 5 and may change again as the investigation continues. Watch for further indicators of compromise from Fortinet, any follow-up guidance from CISA, and reports from incident response firms on who was targeted and what attackers did after gaining access.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

FortinetFortiMailCISAZero-dayEmail security

Earlier coverage of Fortinet

All Fortinet coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.