Skip to content
Critical FortiMail Vulnerability Under

Critical FortiMail Vulnerability Under

First seen 1 Oct 2026, 23:15 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 23:15 UTC
  • •CVE-2026-104286 is a critical vulnerability with a CVSS score of 9.8.
  • •The flaw allows unauthenticated attackers to execute arbitrary code on FortiMail devices.
  • •Fortinet has provided workarounds and is working on security updates for affected versions.

Fortinet has issued a warning regarding a critical vulnerability in FortiMail, tracked as CVE-2026-104286, which is being actively exploited in zero-day attacks. The flaw, rated critical with a CVSS score of 9.8, affects the FortiMail management interface and allows unauthenticated attackers to execute arbitrary commands via crafted HTTP or HTTPS requests. Specifically, it involves improper path traversal and NULL byte handling vulnerabilities. Affected versions include FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9. Fortinet has advised customers to apply workarounds, such as disabling the IBE feature or restricting access to the management interface. Security updates are pending for the affected versions. Indicators of compromise (IOCs) have been published, including specific IP addresses associated with the attacks. Fortinet is coordinating with government agencies, including CISA, regarding the ongoing situation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
CVE-2026-104286 published
Fortinet disclosed a critical vulnerability in FortiMail, affecting multiple versions and allowing unauthorized code execution.
BleepingComputer
2026-10-01
Active exploitation confirmed
Fortinet reported that the vulnerability is being actively exploited in the wild, urging customers to apply workarounds.
BleepingComputer

More articles in this cluster (2)

Following this threat?

Track Fortinet and CVE-2026-104286 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of FortiMail are affected?
The vulnerability affects FortiMail versions 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9.
What should I do if I'm using an affected version?
Apply the recommended workarounds, such as disabling the IBE feature or restricting access to the management interface until patches are available.
Is there a patch available?
No, security updates are not yet available for the affected versions, but Fortinet has indicated that they are forthcoming.