Fortinet has confirmed that a critical, actively exploited vulnerability in its FortiMail secure email gateway lets attackers write arbitrary files to the underlying operating system without providing any credentials — and the U.S. Cybersecurity and Infrastructure Security Agency has already added it to its Known Exploited Vulnerabilities catalog.
What happened
Tracked as CVE-2026-104286 and rated 9.8 out of 10 on the CVSS scale, the bug combines a path traversal weakness with improper handling of null bytes in file paths. Together, they let an unauthenticated attacker send specially crafted HTTP or HTTPS requests to a vulnerable FortiMail appliance and drop files anywhere on the underlying filesystem — a foothold that can be turned into full device compromise.
The flaw affects a wide swath of currently supported FortiMail branches:
- 8.0.0 through 8.0.1
- 7.6.0 through 7.6.6
- 7.4.0 through 7.4.8
- 7.2.0 through 7.2.9
Fortinet has released, or is finalizing, fixed builds for each branch and says exploitation has already been observed against live systems — prompting CISA to require every U.S. federal civilian agency running FortiMail to patch or apply mitigations by October 4, 2026.
Why it matters
Email gateways sit at the edge of the network by design — they have to be internet-facing to do their job, which makes an unauthenticated, pre-auth file-write bug especially dangerous. Attackers don't need stolen credentials or social engineering; a single crafted request is enough to plant a malicious file, and from there pivot toward persistence or lateral movement inside the mail environment. The appliance's trusted position in the mail flow also makes it a high-value target for interception and further compromise.
This isn't an isolated incident. FortiMail joins a run of actively exploited, internet-facing security and networking products disclosed in recent weeks, underscoring how often attackers are targeting the very appliances organizations rely on to defend their perimeter.
What to do
- Patch immediately to the fixed build for your branch (8.0.2+, 7.6.7+, 7.4.9+, or the 7.4 branch and above if you're on 7.2.x).
- If you can't patch right away, disable the IBE (Identity-Based Encryption) feature and restrict the FortiMail management interface so it's reachable only from trusted internal networks — never directly from the internet.
- Hunt for compromise on any internet-facing FortiMail instance: look for unexpected binaries or libraries added to system directories, unplanned modifications to web server configuration files, and outbound connections to unfamiliar IP addresses.
- Treat exposed management interfaces as a standing risk, not just for FortiMail — review every edge appliance for unnecessary internet exposure.
