Hardware3 MIN

Fortinet urges FortiMail mitigations as attackers exploit a flaw before patches arrive

The flaw targets enterprise email-security systems and allows attackers to write files without logging in. Fortinet still lists the fixed releases as upcoming.

Schematic of an enterprise email-security system and its management interface.
Image: INSERT FUTURE · gráfico original / original graphic

Organizations running FortiMail should apply Fortinet’s temporary protections while checking for signs of compromise. The company confirmed active exploitation on October 1. When checked at 05:09 UTC on October 2, its advisory still described fixed releases 8.0.2, 7.6.7 and 7.4.9 as upcoming and urged customers to use the workaround.

FortiMail is enterprise email-security infrastructure, used to filter threats before messages reach employees. This advisory concerns that system, rather than the Gmail or Outlook app someone uses to read mail. The organization’s IT team or managed provider needs to establish whether it runs an affected version.

01

An attacker does not need a login

Tracked as CVE-2026-104286, the flaw lets an unauthenticated attacker send web requests that cause FortiMail to write files outside the intended location. Fortinet lists unauthorized code or command execution as the impact and rates the vulnerability 9.8 out of 10. Its confirmation that attacks are already happening gives administrators a reason to prioritize affected systems now.

Resetting an employee’s email password does not repair this software flaw. It also differs from stealing an existing session, where an attacker reuses evidence that a user has already signed in. Fortinet says this attack requires no authentication in the first place.

  • FortiMail 8.0.0 through 8.0.1. The announced fix is 8.0.2 or later.
  • FortiMail 7.6.0 through 7.6.6. The announced fix is 7.6.7 or later.
  • FortiMail 7.4.0 through 7.4.8. The announced fix is 7.4.9 or later.
  • FortiMail 7.2.0 through 7.2.9. Fortinet directs customers to the 7.4 branch or newer, but the selected release must contain the fix. Moving to an affected 7.4 release would leave the flaw unresolved.
Affected FortiMail branches and fixed versions still listed as upcoming.
Image: INSERT FUTURE · gráfico original / original graphic
02

Protect the management interface or disable IBE

Fortinet offers two workarounds. Administrators can disable IBE, a feature used for email encryption. Alternatively, they can remove internet access to the FortiMail management interface or restrict access to a trusted private network. The management interface is the control panel for the system. Restricting it is not an instruction to shut down all email traffic.

The administrator should check the organization’s configuration and use of the affected functions before making the change. Fortinet provides the exact IBE instruction in its advisory, which is also the place to recheck release availability. A fix listed as upcoming should not be reported as an available patch.

Separate tasks for mitigating exposure, investigating possible compromise and updating when a fix is available.
Image: INSERT FUTURE · gráfico original / original graphic
03

Containment still leaves a separate investigation

CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1 and flags it for forensic triage. Fortinet’s advisory supplies file changes, addresses and log entries that security teams can examine for evidence of compromise. Blocking further exposure does not establish that an earlier intrusion never happened.

If investigators find signs of intrusion, recovery should be coordinated with the incident-response team and the vendor. Separate backups with tested recovery can preserve options, but they cannot replace an investigation of a compromised system. The notices reviewed do not state how many organizations have been affected, and CISA lists use in ransomware campaigns as unknown.

00

The conversation starts here

Sign in with a supporter account to comment. Sign in

Nobody has commented yet. Want to go first?

KEEP READING

You may also like

FRONT PAGE