Cybersecurity 4 min read

Fortinet's Email Gateway Is Under Attack, and No Fixed Version Is Out Yet

A critical FortiMail flaw lets anyone who can reach it over the network write files and run code. Until updates ship, the advice is to switch off one feature or hide the admin interface.

Kenji Tanaka
Developer Tools & Cloud Analyst
Published 2 Oct 2026, 2:06 PM (SGT)
Share:
Illustration of a padlock outline over two computer screens on a blue background Illustration of a padlock outline over two computer screens on a blue background Photo by geralt on Pixabay
Advertisement

2 OCT 2026 — Fortinet warned on 1 October that attackers are exploiting a critical flaw in FortiMail, its email security gateway, and the fixed versions are not yet out. Until they ship, the only protection is a workaround: switch off one feature, or keep the device's management interface off the internet.

FortiMail sits in front of an organisation's mail server and filters what comes in and goes out, so a compromised unit sees the organisation's email.

What the flaw allows

The flaw, CVE-2026-104286, is a path-traversal bug combined with improper null-byte handling. Fortinet's advisory says it "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests", and the company says that can lead to running unauthorised code or commands. It carries a severity score of 9.8 out of 10.

Fortinet's own product security team found the flaw. The advisory says it "has been reported to be exploited in the wild" but gives no date for the first attack, no count of affected devices and no attribution. Asked by BleepingComputer, the company pointed back to the advisory and said it was talking to government agencies, including the US Cybersecurity and Infrastructure Security Agency (CISA).

9.8Severity score out of 10; no login needed
4 branchesFortiMail 7.2, 7.4, 7.6 and 8.0 are affected
0Fixed releases available when the advisory was published
4 OctoberCISA's deadline for US federal agencies to mitigate

Which versions are affected

Affected releases are FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8 and 7.2.0 to 7.2.9. For the three newer branches, the advisory lists 8.0.2, 7.6.7 and 7.4.9 as "upcoming" fixes. Users on 7.2 are told to move to the 7.4 branch or later, but that branch's fix has also not shipped. The advisory's table showed no fixed FortiMail version available on the day it was published.

What the attackers left behind

Fortinet published signs of compromise. On hacked devices, attackers added several files: a library at /data/lib/liblog.so, two executables named webconsole and mailservice, and a file named ld.so.preload. They also modified other files, including the web server configuration. The advisory lists two IP addresses linked to the attacks.

The ld.so.preload file is a standard Linux mechanism that loads a chosen library into every process as it starts, which makes it a common way to keep a foothold. One log entry Fortinet shares shows a new archive account, archive234, set up from the command line to send archives to one of the attackers' IP addresses. BleepingComputer reads that as a sign the attacker configured the gateway to ship archived data to a remote server, which on an email gateway would mean mail.

Advertisement

What to do before the update

Fortinet gives two workarounds. The first is to disable IBE, the gateway's identity-based encryption feature for sending encrypted mail, with three lines in the command-line interface. The second is to block access to the FortiMail management interface from the internet, or limit it to trusted private networks.

Administrators should also check for the files, IP addresses and log entries in the advisory. A device that shows them has already been compromised, and a workaround applied afterwards will not remove what the attacker installed.

The three-day deadline

CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 1 October and gave US federal agencies until 4 October to act. The required action calls for mitigation and forensic triage, so agencies must look for signs of compromise as well as apply the fix.

Three days is now the usual window for new entries, after CISA's deadlines shrank from 21 days. Here the deadline falls before Fortinet has said when the fixed versions will ship, because attackers exploited the flaw before any fix existed. It follows four appliance flaws CISA listed on 22 September.

Advertisement
Kenji Tanaka
Developer Tools & Cloud Analyst

Kenji Tanaka covers developer tools, cloud platforms, DevOps, CI/CD, and software supply-chain topics for RECATOOLS.

View author profile → · Editorial policy

About this byline Kenji Tanaka is a RECATOOLS editorial persona for developer tools, cloud, DevOps, and software supply-chain coverage. Articles are produced and reviewed under RECATOOLS editorial supervision.

Corrections policy

Advertisement