Fortinet has shipped emergency patches for a critical FortiMail vulnerability that attackers are already exploiting, prompting the U.S. Cybersecurity and Infrastructure Security Agency to give federal agencies until Saturday to fix or isolate affected systems.
The flaw, CVE-2026-104286, carries a CVSS severity score of 9.8 out of 10 and requires no authentication to exploit. It combines a path-traversal weakness with a failure to properly handle null-byte characters, which together let an attacker send a crafted HTTP or HTTPS request that writes arbitrary files onto the underlying system, according to reporting on Fortinet's advisory. FortiMail is Fortinet's email-security appliance, widely deployed by corporate and government IT teams to filter spam, phishing and malware from inbound mail.
The bug touches a wide swath of currently supported FortiMail branches: versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and the older 7.2.x line, which Fortinet says should be migrated to 7.4 or later rather than patched in place. Fixed builds — 8.0.2, 7.6.7 and 7.4.9 — are available now.
Already in attackers' hands
The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog on October 1, a day before Fortinet's public advisory, citing evidence of active attacks. Under the binding operational directive that governs the catalog, federal civilian agencies running affected appliances must apply the patch, or complete forensic triage if they cannot patch in time, by October 4. Fortinet credited its own Product Security team, specifically researcher Gwendal Guégniaud, with discovering the issue, and the company has published indicators of compromise, including attacker IP addresses and a list of files known to have been modified in observed intrusions.
Until administrators can apply the fix, Fortinet is recommending two stopgap measures: disabling support for the appliance's IBE (identity-based encryption) feature, which appears to be the exploited entry point, or restricting access to the management interface to trusted internal networks only.
Email gateways sit in an unusually sensitive spot on a corporate network, processing untrusted content from the open internet while holding broad visibility into internal communications, which is why flaws in products like FortiMail have repeatedly drawn sustained attention from both ransomware crews and state-linked hacking groups. Security teams that have not already isolated or patched their FortiMail deployments are being urged to treat this one as an emergency, not a routine update cycle.