Fortinet fixes critical FortiMail flaw exploited by attackers
Fortinet has warned that attackers are exploiting a critical FortiMail vulnerability that allows unauthenticated users to write files to affected systems. Depending on where files are written, attackers may be able to run commands or code on the appliances, making the flaw an urgent security concern.
Tracked as CVE-2026-104286 and rated 9.8 on the CVSS scale, the bug affects FortiMail versions 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9. Fortinet says fixes for several branches are still forthcoming; it advises disabling Identity Based Encryption if possible, restricting management access to trusted private networks, and checking for signs of compromise. CISA has added the flaw to its Known Exploited Vulnerabilities catalogue and set a 4 October mitigation deadline for US federal civilian agencies.
- Attackers are exploiting a critical FortiMail flaw without logging in.
- The vulnerability has a CVSS score of 9.8.
- Fortinet recommends limiting access and checking for compromise.
New here? Start with this
FortiMail is an email security system used by organisations to scan for and block threats in emails. The software runs on dedicated appliances that sit between an organisation's email systems and the internet.
A critical security flaw has been discovered in FortiMail that allows attackers to access these appliances without logging in or authenticating themselves. If an attacker gains access, they could run malicious code on the system and potentially intercept, alter or disrupt an organisation's emails.
The vulnerability affects multiple versions of FortiMail, making it a concern for all organisations using the software. Because attackers are already actively exploiting the flaw, organisations using affected versions face an urgent security threat.
Read the full article at the source →
Originally published by The Register as “Fortinet sounds the alarm over actively exploited FortiMail zero-day”.