If your organization runs Fortinet FortiMail as its email security gateway, stop what you are doing and check your build. CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1 after threat actors were caught exploiting it in the wild as a zero-day. Fortinet confirmed active exploitation, and federal agencies were ordered to remediate by October 4. Here is the catch: for three of the four affected release branches, a patch does not exist yet.
The severity rating is critical – CVSS 9.8 out of 10. An unauthenticated attacker can pull this off with nothing more than crafted HTTP or HTTPS requests. No credentials, no user interaction, no click required.
What the vulnerability is. CVE-2026-104286 is a path traversal flaw (CWE-22) combined with improper neutralization of NULL bytes (CWE-158) in the Identity Based Encryption (IBE) component of the FortiMail management interface. A remote attacker can abuse it to write arbitrary files to the underlying system. In plain terms: an unauthenticated attacker can drop files wherever they want on your email gateway.
And “write arbitrary files” is not a gentle warning. Fortinet’s advisory lists concrete artifacts showing the flaw was used to implant persistent code. Indicators of compromise include added or modified files such as /data/lib/liblog.so, a new entry in /data/etc/ld.so.preload, modified system binaries like /bin/smit and /data/bin/webconsole, a changed /data/bin/mailservice, an altered /data/etc/httpd.conf, and a suspicious /data/migadmin.tar.gz. That combination – a preloaded shared library plus a modified web server configuration – points to attackers establishing persistence on the appliance, not just poking at it. Fortinet also flagged two source IP addresses tied to the attacks and an archive-style account named “archive234” forwarding data to a remote server.
Affected versions. FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.
The patch gap. This is the part that should scare you. Fortinet has released a fixed version for only one branch. If you are on 7.2.0-7.2.9, you can move to the 7.4 branch or later. But for 7.4, 7.6, and 8.0, the fixes are listed as upcoming releases – 7.4.9, 7.6.7, and 8.0.2 respectively – with no release dates announced. Until those land, exposed appliances have no patch available, only workarounds.
What you need to do right now.
Disable the IBE feature if you do not use it. Fortinet’s official workaround is to stop IBE support from the CLI: config system encryption ibe then set status disable then end. If you are not actively using Identity Based Encryption, remove that attack surface immediately.
Stop exposing the management interface to the internet. This is the single highest-value step. If the FortiMail admin interface is reachable from the public internet, take it offline or restrict it so only trusted private networks can reach it. Most of these edge-appliance attacks depend on the management console being internet-facing. Cut that off and your exposure drops dramatically even before a patch exists.
Hunt for compromise before you patch. Patching closes the door – it does not remove an attacker who is already inside. Review your FortiMail appliances for the listed indicator files and hashes, check for unrecognized archive accounts or outbound destinations, and look for the log signatures Fortinet published (root cron jobs involving /migadmin, failed internal logins, IBE decryption errors referencing invalid base64). If you find any, assume the box is compromised and start full incident response. Preserve forensic evidence before applying updates, because patching can erase the very artifacts you need.
Block the known source IPs. Add 79.141.169.187 and 45.129.0.192 to your blocklists, though treat that as a band-aid – attackers rotate infrastructure.
Watch for the fixes and deploy the moment they land. Subscribe to Fortinet PSIRT advisories (FG-IR-26-175) and have a deployment plan ready for 7.4.9, 7.6.7, and 8.0.2. When a patch is available, there is no reason to wait.
Do not wait on this one. A KEV-listed zero-day with confirmed preloaded-library persistence on your email gateway is about as urgent as it gets. If you have FortiMail exposed, assume it is being probed right now – disable IBE, kill internet access to management, and hunt for the indicators before the patch ships.