Skip to content
News briefSC-2026-0322

A FortiMail flaw with no patch yet

Fortinet says an unauthenticated file-write bug rated 9.8 is already being exploited, and offers workarounds while fixes are still pending.

2 minEnterprise CyberSecFresh · 1 Oct

Fortinet has warned customers that CVE-2026-104286, a critical flaw in the FortiMail management interface, is being exploited in zero-day attacks. The advisory describes a combination of path traversal and improper handling of NULL characters that lets an unauthenticated attacker write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. It carries a CVSS score of 9.8.

The affected range is wide: FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Gwendal Guegniaud of Fortinet's own product security team found the bug internally.

What administrators can do now

For most of those versions there is nothing to install yet. Fortinet lists 7.4.9, 7.6.7 and 8.0.2 as upcoming releases containing the fix, and tells customers on 7.2 to move to the 7.4 branch or later. Until the fixed builds appear, the vendor's workarounds are to disable identity-based encryption support, or to take the management interface off the internet and restrict it to trusted private networks.

Fortinet has also published indicators of compromise from the attacks, listing files added or modified on compromised systems with their hashes, among them a shared library under the data directory and a modified system binary. That detail is what makes the advisory usable before a patch exists: an administrator who cannot upgrade can at least check whether the box has already been touched.

The pattern is familiar enough to be worth stating plainly. A mail gateway sits at the edge by design, its management interface is often reachable because that is convenient, and an unauthenticated write primitive on such a device is as good as full control. Restricting that interface is the measure that would have blunted this one regardless of the specific bug.

Retold from BleepingComputer. This is a summary in our own words; follow the link for the original reporting.

Read next

Across the network

Desks that share a zone with this one on the BITBRIEF coverage map.

Terms defined