SOCLYDE logo
Current languageEN
Cybersecurity newsFortinetFortiMailCVE

Fortimail: a flaw exploited before a fix

CVE-2026-104286 is being exploited against FortiMail. Review affected versions, Fortinet's temporary guidance and the checks to run.

By Soclyde Team

A technician checks an email security appliance in a network closet

In summary

  • Fortinet confirms active exploitation of CVE-2026-104286 in the FortiMail management interface.
  • The flaw can let an unauthenticated attacker write files to an appliance through crafted HTTP or HTTPS requests.
  • Check versions, apply Fortinet's mitigations and look for signs of unauthorized access.

Explore next

Soclyde resources

Article contents

On October 1, 2026, Fortinet published an advisory for CVE-2026-104286 and reported active exploitation targeting FortiMail. The flaw affects the management interface: a crafted HTTP or HTTPS request may let an unauthenticated attacker write files to the appliance. CISA subsequently added the vulnerability to its KEV catalog.

Fortinet has not publicly counted compromised appliances. A KEV listing confirms known exploitation, but does not establish that a particular installation was affected.

What Fortinet confirmed

The advisory describes a path traversal combined with improper handling of a null character. FortiMail 8.0, 7.6, 7.4 and 7.2 branches are affected within the ranges listed in the FAQ. Network exposure of the management interface is central to assessing risk.

Fortinet has not named the attackers or disclosed how many organizations were affected. Do not infer compromise from a version number alone; review access and system logs as well.

Actions to take now

Inventory appliances and software branches, then compare them with the vendor advisory. The announced fixed releases are 7.4.9, 7.6.7 and 8.0.2. Fortinet advises 7.2 devices to migrate to 7.4 or later; do not stop at 7.4.0 through 7.4.8, which remain vulnerable. Verify availability and the target release in the official advisory. Until a fix is available, Fortinet recommends disabling IBE support (config system encryption ibe, set status disable, end) or restricting management-interface access to trusted private networks.

Preserve logs before cleaning or rebuilding anything. Look for unexpected files or accounts, unusual administrator access and abnormal scheduled tasks. If you find concrete signs of intrusion, isolate the appliance under your response plan, preserve evidence and contact your incident-response team.

Why email security needs a focused review

An email security appliance sits between mail flows and administrative systems. A confirmed compromise warrants a review of privileged accounts, routing rules and technical secrets it could reach. After remediation, rotate exposed credentials in a controlled order.

How Soclyde fits

Soclyde does not patch FortiMail or detect an intrusion. Its vault can help a team locate administration, relay and backup credentials so they can be rotated and reassigned in a controlled way.

The takeaway

CVE-2026-104286 is being exploited. Check every FortiMail appliance, follow vendor guidance and preserve evidence if activity looks suspicious. Read the team password management guide or contact Soclyde.

Frequently asked questions

Which devices are affected?

Fortinet lists FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9. Check the vendor's live advisory for the current branch guidance.

Is a fix available for every release?

Fortinet lists 7.4.9, 7.6.7 and 8.0.2 as upcoming fixed releases. For branch 7.2, it recommends migrating to 7.4 or later, but versions 7.4.0 through 7.4.8 remain vulnerable. Verify that the destination release is fixed before upgrading.

What should I do if FortiMail is internet-facing?

Follow the vendor's official temporary guidance, restrict network access to its management interface and preserve logs. If you find evidence of compromise, start your incident-response process.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading