2 OCT 2026 — Fortinet warned on 1 October that attackers are exploiting a critical flaw in FortiMail, its email security gateway, and the fixed versions are not yet out. Until they ship, the only protection is a workaround: switch off one feature, or keep the device's management interface off the internet.
FortiMail sits in front of an organisation's mail server and filters what comes in and goes out, so a compromised unit sees the organisation's email.
What the flaw allows
The flaw, CVE-2026-104286, is a path-traversal bug combined with improper null-byte handling. Fortinet's advisory says it "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests", and the company says that can lead to running unauthorised code or commands. It carries a severity score of 9.8 out of 10.
Fortinet's own product security team found the flaw. The advisory says it "has been reported to be exploited in the wild" but gives no date for the first attack, no count of affected devices and no attribution. Asked by BleepingComputer, the company pointed back to the advisory and said it was talking to government agencies, including the US Cybersecurity and Infrastructure Security Agency (CISA).
Which versions are affected
Affected releases are FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8 and 7.2.0 to 7.2.9. For the three newer branches, the advisory lists 8.0.2, 7.6.7 and 7.4.9 as "upcoming" fixes. Users on 7.2 are told to move to the 7.4 branch or later, but that branch's fix has also not shipped. The advisory's table showed no fixed FortiMail version available on the day it was published.
What the attackers left behind
Fortinet published signs of compromise. On hacked devices, attackers added several files: a library at /data/lib/liblog.so, two executables named webconsole and mailservice, and a file named ld.so.preload. They also modified other files, including the web server configuration. The advisory lists two IP addresses linked to the attacks.
The ld.so.preload file is a standard Linux mechanism that loads a chosen library into every process as it starts, which makes it a common way to keep a foothold. One log entry Fortinet shares shows a new archive account, archive234, set up from the command line to send archives to one of the attackers' IP addresses. BleepingComputer reads that as a sign the attacker configured the gateway to ship archived data to a remote server, which on an email gateway would mean mail.
What to do before the update
Fortinet gives two workarounds. The first is to disable IBE, the gateway's identity-based encryption feature for sending encrypted mail, with three lines in the command-line interface. The second is to block access to the FortiMail management interface from the internet, or limit it to trusted private networks.
Administrators should also check for the files, IP addresses and log entries in the advisory. A device that shows them has already been compromised, and a workaround applied afterwards will not remove what the attacker installed.
The three-day deadline
CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 1 October and gave US federal agencies until 4 October to act. The required action calls for mitigation and forensic triage, so agencies must look for signs of compromise as well as apply the fix.
Three days is now the usual window for new entries, after CISA's deadlines shrank from 21 days. Here the deadline falls before Fortinet has said when the fixed versions will ship, because attackers exploited the flaw before any fix existed. It follows four appliance flaws CISA listed on 22 September.