Fortinet FortiMail zero-day exposes email gateways to unauthenticated attackers
Attackers are exploiting a critical FortiMail flaw that lets them write files to the email appliance without logging in, Fortinet warned. Because the gateway handles organisations’ email, a compromise can expose messages and credentials; patches are not yet available, so Fortinet recommends disabling identity-based encryption or restricting internet access to the management interface.
Bottom line — CISA has set 4 October for US federal agencies to mitigate CVE-2026-104286 and check whether systems were already compromised.
Go deeper 6
-
The vulnerability, CVE-2026-104286, is rated 9.8 and affects FortiMail versions in the 7.2, 7.4, 7.6 and 8.0 branches, The Register reports.
-
Fortinet says fixes for affected branches are upcoming; it has not said when attacks began or how many customers may have been compromised, The Register reports.
-
Disabling identity-based encryption removes the vulnerable attack surface, but also suspends that encrypted-mail feature, Tech Times reports.
-
Fortinet also advises keeping the management interface off the public internet or limiting it to trusted private networks, according to Cybersecurity Dive.
-
The Register cautions that applying a workaround will not remove files or persistence mechanisms attackers may already have planted; administrators should check for signs of compromise.
-
Roman Y. Sannikov of iCounter told SC Media that suspicious changes to system files and web-server configuration suggest attackers are seeking persistent access.