Organizations running FortiMail should apply Fortinet’s temporary protections while checking for signs of compromise. The company confirmed active exploitation on October 1. When checked at 05:09 UTC on October 2, its advisory still described fixed releases 8.0.2, 7.6.7 and 7.4.9 as upcoming and urged customers to use the workaround.
FortiMail is enterprise email-security infrastructure, used to filter threats before messages reach employees. This advisory concerns that system, rather than the Gmail or Outlook app someone uses to read mail. The organization’s IT team or managed provider needs to establish whether it runs an affected version.
An attacker does not need a login
Tracked as CVE-2026-104286, the flaw lets an unauthenticated attacker send web requests that cause FortiMail to write files outside the intended location. Fortinet lists unauthorized code or command execution as the impact and rates the vulnerability 9.8 out of 10. Its confirmation that attacks are already happening gives administrators a reason to prioritize affected systems now.
Resetting an employee’s email password does not repair this software flaw. It also differs from stealing an existing session, where an attacker reuses evidence that a user has already signed in. Fortinet says this attack requires no authentication in the first place.
- FortiMail 8.0.0 through 8.0.1. The announced fix is 8.0.2 or later.
- FortiMail 7.6.0 through 7.6.6. The announced fix is 7.6.7 or later.
- FortiMail 7.4.0 through 7.4.8. The announced fix is 7.4.9 or later.
- FortiMail 7.2.0 through 7.2.9. Fortinet directs customers to the 7.4 branch or newer, but the selected release must contain the fix. Moving to an affected 7.4 release would leave the flaw unresolved.

Protect the management interface or disable IBE
Fortinet offers two workarounds. Administrators can disable IBE, a feature used for email encryption. Alternatively, they can remove internet access to the FortiMail management interface or restrict access to a trusted private network. The management interface is the control panel for the system. Restricting it is not an instruction to shut down all email traffic.
The administrator should check the organization’s configuration and use of the affected functions before making the change. Fortinet provides the exact IBE instruction in its advisory, which is also the place to recheck release availability. A fix listed as upcoming should not be reported as an available patch.

Containment still leaves a separate investigation
CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1 and flags it for forensic triage. Fortinet’s advisory supplies file changes, addresses and log entries that security teams can examine for evidence of compromise. Blocking further exposure does not establish that an earlier intrusion never happened.
If investigators find signs of intrusion, recovery should be coordinated with the incident-response team and the vendor. Separate backups with tested recovery can preserve options, but they cannot replace an investigation of a compromised system. The notices reviewed do not state how many organizations have been affected, and CISA lists use in ransomware campaigns as unknown.
The conversation starts here
Sign in with a supporter account to comment. Sign in




Nobody has commented yet. Want to go first?