FortiMail Zero-Day: Unauthenticated File Writes on Your Mail Gateway Are Being Exploited

by Rebecca Sutton

Fortinet has confirmed that attackers are already exploiting a FortiMail zero-day, and the flaw needs no password to abuse. Tracked as CVE-2026-104286 with a CVSS score of 9.8, it lets a remote stranger write files onto an email security appliance that sits at the edge of your network.

Battered red postboxes, a metaphor for the exposed FortiMail zero-day mail gateway

What the FortiMail zero-day actually does

The bug is a path traversal combined with a null byte injection. In plain terms, the appliance does not check the file path in a request properly. An attacker can add ../ sequences to climb out of the folder meant to confine them. A null character then fools the filename check. The result is an arbitrary file write.

Fortinet says the attacker only needs to send crafted HTTP or HTTPS requests. No login is required. SecurityWeek reports that a file write like this can lead to code or command execution on the box, which is why the score is so high.

Fortinet’s own advisory describes the status as “exploited in the wild”. The vendor’s wording to customers, as quoted by SecurityWeek, was blunt: “This has been reported to be exploited in the wild; customers are urged to apply the workaround.” Neither Fortinet nor CISA has said who is behind the attacks or who has been hit.

Which versions are affected

Every supported branch is in scope, according to the Fortinet advisory FG-IR-26-175:

  • FortiMail 8.0.0 through 8.0.1
  • FortiMail 7.6.0 through 7.6.6
  • FortiMail 7.4.0 through 7.4.8
  • FortiMail 7.2.0 through 7.2.9

The fixed releases are 8.0.2, 7.6.7 and 7.4.9. Customers on 7.2 are told to move to the 7.4 branch or later, because no 7.2 fix is planned.

Patch timing is murky. SecurityWeek reported at the time that those releases were still upcoming, with no date. Advisories change fast, so check the Fortinet page before you plan around a patch that may not exist yet.

FortiMail zero-day workarounds that matter today

Fortinet’s advisory lists three stopgaps. Disable the IBE feature, restrict access to the webmail and management interfaces to trusted networks, or put a web application firewall rule in front that blocks POST requests to /ibe containing ../. The advisory also publishes two IP addresses linked to the attacks, 79.141.169.187 and 45.129.0.192, which are worth searching for in your logs.

The second workaround is the one that should make you uncomfortable. If your mail gateway’s web interface is reachable from the whole internet, you have already given every scanner a chance at it.

Why a mail gateway is such a good target

An email security gateway sees everything. Inbound mail, outbound mail and attachments all pass through it. So do many of the credentials used to relay or inspect them. It is also a locked-down box that nobody logs into. No endpoint agent watches it, and few teams read its logs.

That makes a compromise quiet and valuable. We made the same point when another vendor’s email gateway came under attack: the tool you bought to reduce risk becomes the way in. Edge appliances from Fortinet, Cisco and Citrix keep appearing in exploited-vulnerability lists for exactly this reason, and our plain patching checklist covers the routine.

What CISA’s listing tells you

CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalogue on 1 October 2026. Under its binding directive BOD 26-04, US federal agencies get just three days to act. UK organisations are not bound by that, but the catalogue is a useful signal: it only lists flaws with confirmed exploitation, so it is a short and honest to-do list.

What to do this week about the FortiMail zero-day

  1. Find your FortiMail units. Include virtual machines and any that a previous supplier set up.
  2. Apply the workaround now. Do not wait for a maintenance window if the interface faces the internet.
  3. Hunt for signs of compromise. Check web logs for POST requests to /ibe with traversal strings, and for the two IP addresses above. Look for system files that changed without a change ticket.
  4. Patch when a fixed build is available, then rotate any credentials stored on the appliance if you find evidence of access.
  5. Test your exposure. An external network penetration test shows which of your management interfaces answer the internet, usually including a few that people forgot.

If this term is new to you, our plain-English guide for UK businesses explains the idea. The short version: you cannot patch a flaw that has no patch, so cutting exposure is the only real defence.

The wider lesson

Nobody should have to guess whether an appliance is exposed. Keep a list of every internet-facing management page you own. Treat each new entry as a decision that needs a reason. When the next bug lands, half the work is done.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like