DKDKCISSPSearch
Vulnerabilities

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.

DKCISSP News DeskBleepingComputer2 Oct 2026, 4:12 am
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.

Fortinet says the flaw is being actively exploited and is urging customers to apply the shared workarounds until a security update can be installed.

Until patched versions are available, Fortinet says admins can mitigate the flaw by disabling IBE feature support using the following commands: As an alternative workaround, administrators can disable access to the FortiMail management interface from the Internet or restrict access to trusted private networks.

Fortinet has not disclosed when the flaw was first exploited, how many systems were compromised, or who is behind the attacks.

FortiMail 7.2 users can patch the vulnerability by upgrading to the 7.4 branch or later.

Gwendal Guégniaud of Fortinet's Product Security team discovered the vulnerability internally, and it affects FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, and FortiMail 7.2.0 through 7.2.9.

This could indicate that the attacker configured the compromised FortiMail appliance to send archived data to a remote server.

For affected FortiMail 7.4, 7.6, and 8.0 installations, security updates are not yet available, with Fortinet listing FortiMail 7.4.9, 7.6.7, and 8.0.2 as upcoming versions containing the fix.

The vulnerability is rated critical, with a CVSS score of 9.8, and affects the FortiMail management interface.

Fortinet also published indicators of compromise (IOCs) associated with the attacks, including several files that were added or modified on compromised systems.

What happened

Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.

Fortinet says the flaw is being actively exploited and is urging customers to apply the shared workarounds until a security update can be installed.

What changed

Until patched versions are available, Fortinet says admins can mitigate the flaw by disabling IBE feature support using the following commands: As an alternative workaround, administrators can disable access to the FortiMail management interface from the Internet or restrict access to trusted private networks.

Fortinet has not disclosed when the flaw was first exploited, how many systems were compromised, or who is behind the attacks.

Who is affected

FortiMail 7.2 users can patch the vulnerability by upgrading to the 7.4 branch or later.

Gwendal Guégniaud of Fortinet's Product Security team discovered the vulnerability internally, and it affects FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, and FortiMail 7.2.0 through 7.2.9.

Why it matters

This could indicate that the attacker configured the compromised FortiMail appliance to send archived data to a remote server.

For affected FortiMail 7.4, 7.6, and 8.0 installations, security updates are not yet available, with Fortinet listing FortiMail 7.4.9, 7.6.7, and 8.0.2 as upcoming versions containing the fix.

Technical details

The vulnerability is rated critical, with a CVSS score of 9.8, and affects the FortiMail management interface.

Fortinet also published indicators of compromise (IOCs) associated with the attacks, including several files that were added or modified on compromised systems.

When BleepingComputer asked for more information about the exploitation activity, Fortinet referred customers to the advisory and said it is coordinating with government agencies, including CISA.

Response

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

What remains unknown

Fortinet has not disclosed when the flaw was first exploited, how many systems were compromised, or who is behind the attacks.

Attribution

BleepingComputer: Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmKiteworks patches max severity code injection vulnerabilityBleepingComputer · 1 Oct 2026, 7:21 pmApple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery PathThe Hacker News · 1 Oct 2026, 11:24 am