FortiMail CVE-2026-104286: Exploited 9.8 Flaw Lets Unauthenticated Requests Write Files
Security / news
FortiMail CVE-2026-104286: Exploited 9.8 Flaw Lets Unauthenticated Requests Write Files
Fortinet's advisory lists a workaround and fixed builds for three release branches; the 7.2 branch gets none.

An unauthenticated attacker who can send HTTP or HTTPS requests to a FortiMail appliance's webmail interface can write arbitrary files to the underlying system, provided the Identity-Based Encryption (IBE) feature is enabled. Fortinet rates CVE-2026-104286 at 9.8 and marks it as known exploited.
CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on October 1, with a federal due date of October 4. The weakness is a path traversal (CWE-22) combined with improper handling of NULL bytes (CWE-158).
Affected builds and fixes
Fortinet's advisory FG-IR-26-175 was published October 1 and updated October 5. As of that update it lists fixed builds for three branches. The oldest branch is left without one.
| FortiMail branch | Affected | Fixed in |
|---|---|---|
| 8.0 | 8.0.0 to 8.0.1 | 8.0.2 and later |
| 7.6 | 7.6.0 to 7.6.6 | 7.6.7 and later |
| 7.4 | 7.4.0 to 7.4.8 | 7.4.9 and later |
| 7.2 | 7.2.0 to 7.2.9 | Upgrade to 7.4 or later |

The sequence of dates is the part worth reading closely. watchTowr's FAQ describes no fixed release when the advisory first appeared on October 1 and gives only the workaround. The KEV due date of October 4 therefore arrived a day before the advisory's October 5 update. The sources I read do not say when the fixed builds became available.
The workaround and what it costs
Fortinet lists three mitigations:
- Disable the IBE feature with the CLI sequence
config system encryption ibe,set status disable,end. - Restrict webmail access from the internet to trusted networks only.
- Put a web application firewall in front that blocks POST requests to
/ibecontaining../.
Disabling IBE removes the vulnerable feature, so the cost falls on whatever mail an organisation sends through it, a figure the advisory does not give.
The score here is accurate on its own terms. Network reachable, no authentication, no user interaction and write access to the system justify 9.8. What the advisory does not spell out is what an attacker does with a file write on the appliance, or how many systems were hit. It says exploitation was reported and lists indicators (suspicious files, hashes and attacker IP addresses) for comparison.
What operators should do
Check the build number first. On 8.0, 7.6 or 7.4, move to the fixed build. On 7.2, no patch exists, so plan the move to 7.4 or later and apply the IBE and webmail restrictions meanwhile. Compare the appliance against Fortinet's indicator list, since CISA's catalog entry carries a forensic-triage flag.
A mail gateway stores messages and credentials, so its compromise tends to end in disclosure of the kind covered in Denmark's CPR breach of 8.8 million records, though the two incidents are unrelated. For another October KEV entry with a three-day deadline, see the Zammad entry.
The advisory credits the discovery to Gwendal Guégniaud of Fortinet's Product Security team. Fortinet has not said how the attackers learned of the flaw before the advisory appeared.
Sources
More in Security
- 01Pwn2Own Ireland 2026 Day One: Seven of 20 Listed Entries Were Collisions, and OpenAI Codex Fell to Argument InjectionSamsung's Galaxy S26 was hit three times, Sonos and Philips Hue each twice or more, and a Google Pixel 10 attempt ran out of time. Vendors get 90 days before details go public.
- 02Atlassian CVE-2026-21589: A 9.3 File-Access Flaw Hits Every Data Center Version of Eight ProductsAn unauthenticated request can read a file from the web root if the attacker already knows its exact path. Atlassian reports no exploitation and has released fixes for each product line.
- 03WordPress CVE-2026-87902: A Page-Template Bug in Every Release Since 4.7, Patched in 7.1.2The 9.2 rating describes a file include; code execution needs a theme folder starting with page- and a PHP setting, but probes began five hours after the patch.
- 04Citrix's September 27 NetScaler Fix Does Not Cover CVE-2026-88779, Now on CISA's Exploited ListBuilds that closed two exploited zero-days stay vulnerable to a SAML flaw that CISA added on October 4 with a three-day deadline.