Skip to content
Quantum Secure Labs
Cybersecurity News

Fortinet warns of a critical FortiMail flaw exploited as a zero-day and still unpatched

Fortinet has confirmed attackers are already exploiting CVE-2026-104286, a critical FortiMail flaw that lets them write files to the system without authenticating. It affects the 7.2, 7.4, 7.6 and 8.0 branches, and the…

By Quantum Secure Labs4 min read
Bandeja de entrada de correo electrónico en la pantalla de un ordenador portátil en una oficina
In this article

Fortinet has confirmed attackers are already exploiting CVE-2026-104286, a critical FortiMail flaw that lets them write files to the system without authenticating. It affects the 7.2, 7.4, 7.6 and 8.0 branches, and the last three still have no patch. If you run FortiMail, apply the FG-IR-26-175 mitigations today and restrict web access.

The essentials

  • INCIBE-CERT published a severity 5 (critical) advisory on 2 October. Affected versions: 8.0.0 to 8.0.1, 7.6.0 to 7.6.6 and 7.4.0 to 7.4.8. The 7.2 branch is also on the list.
  • According to CISA, it is a path traversal combined with improper neutralization of NULL bytes. An unauthenticated attacker can write arbitrary files using crafted HTTP or HTTPS requests.
  • There is no update yet for 7.4, 7.6 and 8.0. Fortinet says the fix will ship in 7.4.9, 7.6.7 and 8.0.2, according to BleepingComputer.
  • CISA added it to its KEV catalog and required US federal agencies to carry out forensic analysis and mitigate before 4 October. It does not know whether it is used in ransomware campaigns.
  • A Fortinet product security team found the flaw internally. Fortinet published advisory FG-IR-26-175 with the mitigations on Thursday 1 October.

Does it affect me if a provider manages my email?

Yes, if that provider uses FortiMail for your company. FortiMail is a common email gateway among SMEs and MSPs. It may sit in your office or in your IT provider's infrastructure, and you may never have seen it by name. The only way to know is to ask. Don't assume your provider has already checked: the advisory is barely four days old.

Why is a flaw in the email gateway so serious?

Three reasons add up. First, that box filters all corporate email: invoices, contracts, customer data. Second, it is usually exposed to the Internet, because it has to receive mail and often offers webmail. Third, the attacker needs no credentials: crafted web requests are enough to write files to the system. And this is not theoretical: Fortinet says it is being actively exploited.

What if I'm still on the 7.2 branch?

Fortinet says the path for 7.2 is to migrate to 7.4 or later. The catch is that 7.4 has no patch either until 7.4.9 ships. Until then, your real protection is the advisory's mitigations and shutting down web access.

What to do today

  1. Ask your IT provider or MSP whether there are FortiMail instances in your company and which version they run. Get the answer in writing.
  2. Apply the mitigations in Fortinet's FG-IR-26-175 advisory now.
  3. Limit HTTP/HTTPS access to administration and webmail to trusted IPs. If nobody uses it from outside, close it.
  4. Review logs for unusual requests and for new or unexpected files on the device. CISA requires forensic analysis from its agencies for a reason.
  5. Check whether versions 7.4.9, 7.6.7 or 8.0.2 are out yet and plan the update as soon as they are.
  6. If you find signs of compromise, assess whether you must notify a breach to the Spanish data protection authority (AEPD) within 72 hours under GDPR and, if you are an essential or important entity, under NIS2.
  7. Subscribe to INCIBE-CERT advisories so you don't find out late next time.

What it means for an SME

An unpatched zero-day takes away the easy answer of "just update". You have to shrink the attack surface and watch. The most useful move today is to close the gateway's web access to anyone who doesn't need it: it cuts off the described attack path and doesn't depend on Fortinet releasing anything.

The second lesson is about inventory. Many 20- or 50-person companies don't know which device filters their email or who updates it. If your answer today is "I don't know", the risk isn't just this CVE but the next one. Ask your provider for a list of Internet-facing devices, their versions and who is responsible for each.

Waiting for the patch with your arms folded isn't an option either. Attackers may have got in before the advisory existed, so reviewing logs is not optional. If you have nobody who can do it with sound judgement, now is the time to get outside cybersecurity support, rather than after a breach.

Frequently asked questions

Is there a patch for FortiMail yet?

Not for the 7.4, 7.6 and 8.0 branches at the time of the advisory. Fortinet says the fix will come in 7.4.9, 7.6.7 and 8.0.2. Until then, apply the FG-IR-26-175 mitigations.

Does the attacker need a password?

No. According to CISA, an unauthenticated attacker can write arbitrary files using crafted HTTP or HTTPS requests.

Is it being used in ransomware attacks?

CISA says it doesn't know. It does confirm, as Fortinet does, that the flaw is being actively exploited.

Sources

Worried about a threat like this one?

We review your exposure and show you how to protect yourself.

See our cybersecurity service

Want to apply these ideas to your business?

Tell us about your case and we'll show you how to apply these strategies to your project.