Your FortiMail management plane has a Saturday deadline

By George Bailey   Published: 10/02/26   4 min read

Fortinet confirmed active exploitation of a critical path-traversal flaw in the FortiMail management interface. An unauthenticated attacker who can reach that interface can write arbitrary files to the appliance — and CISA’s federal due date is Saturday, October 4, with forensic triage required.

Patches for several trains are still upcoming. Until they land, Friday morning is the window to pull management off the internet, disable IBE if you can, and hunt Fortinet’s published indicators before the weekend clock.

Your secure-mail appliance is also a management plane. Attackers already treat it that way.

What happened

On October 1, 2026, Fortinet published FG-IR-26-175 for CVE-2026-104286. The bug combines path traversal (CWE-22) with improper null-byte handling (CWE-158) in the FortiMail GUI. Crafted HTTP or HTTPS requests from an unauthenticated attacker can write arbitrary files on the underlying system and execute unauthorized code or commands. Fortinet rates it critical (CVSS 9.8) and says the flaw is being exploited in the wild. The issue was discovered internally by Gwendal Guégniaud of Fortinet Product Security.

Affected releases: FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. FortiMail 7.2 can move to the 7.4 branch or later. Fixed builds for 7.4 / 7.6 / 8.0 are listed as upcoming: 7.4.9, 7.6.7, and 8.0.2.

Until those builds ship, Fortinet’s workaround is to disable Identity-Based Encryption (IBE) support, or disable / restrict internet access to the FortiMail management interface to trusted private networks only. CISA added CVE-2026-104286 to KEV the same day and ordered federal civilian agencies to perform forensic triage and mitigate by October 4, 2026 under BOD 26-04.

Why it matters

FortiMail sits on the email perimeter and often exposes a management path that operators treat as “internal.” Unauthenticated file write on that path is a foothold into the mail stack — credentials, archives, and outbound relays included. Fortinet published concrete IoCs: planted libraries and binaries under /data, a modified /bin/smit, an ld.so.preload hook, archive accounts pointing at attacker IPs, and cron activity around /migadmin.

The Saturday federal clock is a useful forcing function even outside government. Workarounds first; patches when they land; hunt as if compromise is plausible.

What to do first

Forward this

If you own email security or FortiMail: Fortinet confirmed active exploitation of an unauthenticated management-interface file-write bug (CVE-2026-104286). CISA’s federal due date is Saturday, October 4. Please confirm every FortiMail management GUI is off the public internet (or IBE is disabled), that Fortinet’s published IoCs were checked, and that an upgrade to a fixed build is scheduled the moment 7.4.9 / 7.6.7 / 8.0.2 ship.

Details

Hunt / verify

Slack paste: FortiMail CVE-2026-104286 actively exploited — pull management off the internet / disable IBE today, hunt Fortinet IoCs, federal due Sat Oct 4, upgrade when 7.4.9 / 7.6.7 / 8.0.2 land.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.