Fortinet is telling customers to lock down FortiMail by hand. Attackers are already abusing a critical flaw in the email gateway, and there is no finished patch to install.
The bug, tracked as CVE-2026-104286, rates 9.8 on the CVSS scale. It blends a path-traversal error with sloppy handling of null characters in FortiMail’s web interface, letting an unauthenticated attacker push arbitrary files onto the appliance with crafted HTTP or HTTPS requests.
Write to the right spot and you can run code or commands on the box.
Affected builds run from 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet credits Gwendal Guegniaud of its own Product Security team with the find. Fixes are promised in 8.0.2, 7.6.7, and 7.4.9, none of which have shipped yet. Anyone on the 7.2 branch is told to move to 7.4 or later.
Until then, admins get workarounds. Disable identity-based encryption if the site does not rely on it, and keep the management interface off the public internet.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1 and gave federal civilian agencies until October 4 to act. Fortinet has published files, IP addresses, and log entries tied to the attacks so defenders can hunt for signs of compromise, though it has stayed quiet on who is behind them or how many sites are hit.
