securityonline.info 1 Oct 2026, 22:08 UTC

FortiMail Flaw Exploited in the Wild, Exposing Corporate Networks

FortiMail Flaw Exploited in the Wild, Exposing Corporate Networks
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

FORTINET’S FortiMail appliance is actively exploited due to a path traversal flaw tracked as CVE-2026-104286, rated CVSS 9.8. The vulnerability arises from a combination of path traversal (CWE-22) and poor handling of NULL bytes (CWE-158), enabling unauthenticated attackers to write files outside the intended directory and potentially execute arbitrary code or commands.

Fortinet notes the flaw has been reported as exploited in the wild, and CISA has added it to its Known Exploited Vulnerabilities (KEV) catalog as of 1 October 2026, signalling active risk for organisations. FortiMail appliances commonly serve as gateways for large firms, so a compromised unit could expose mail traffic and provide attackers a foothold inside affected networks.

Affected products include FortiMail 8.0.0 and 7.6.0–7.6.5, 7.4.0–7.4.6, 7.2.0–7.2.9, and 7.0.0–7.0.9. At the time of reporting, Fortinet had not released a fixed build; users are advised to apply the vendor workaround outlined in FG-IR-26-175, which HOL interprets as disabling Identity Based Encryption (IBE) or restricting management access to trusted internal networks.

Planned fixes are expected in FortiMail 8.0.2, 7.6.7, and 7.4.9, with migration guidance for users on 7.2 to move to 7.4 or later, while the 7.0 branch has no listed fix. Organisations should also hunt for signs of compromise, such as altered binaries, suspicious library preloads, or unusual outbound connections, while the vendor and HOL guidance are followed.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline