TL;DR: On Wednesday, the company that sells email security to much of the Fortune 500 told its customers to go switch a feature off. By the next morning, the US cyber agency had added the bug to its catalog of flaws under active attack and given federal agencies until October 4 to deal with it. For most organizations running FortiMail, there is still nothing to install.
What Happened?
A critical flaw in FortiMail, the vendor’s email security gateway, is being exploited in the wild. It is tracked as CVE-2026-104286 and carries a CVSS score of 9.8, close to the ceiling.
The bug lives in the web management interface, specifically the component behind identity-based encryption. It combines a path traversal weakness with sloppy handling of null characters. An attacker with no account and no password can send a crafted HTTP or HTTPS request and write files anywhere on the underlying system. The vendor lists the impact as running unauthorized code or commands.
Four branches are affected: 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The repaired builds for the first three are described as upcoming, which means they do not exist yet. Customers on 7.2 are told to move to the 7.4 branch or later. There is no virtual patch either.
The vendor’s product security team found the flaw internally. It was already being used in attacks when they found it. Nobody has said who is behind the campaign, when it started, or how many appliances were taken.
The Impact
The published indicators tell a sharper story than the severity score does.
On compromised appliances, attackers added four files and modified three more. One addition was an ld.so.preload entry, which quietly forces a planted library into running processes. The attackers also rewrote the web server configuration.
Then came the part that should worry mail administrators most. The attackers created an archive account from the command line and pointed it at a server they controlled, writing to a directory called /uploads. A mail gateway reads every message the organization sends and receives. Turning its own archive function into an outbound feed is a clean way to steal mail without deploying anything that looks like malware.
Two factors make this worse than a normal critical bug. The appliance is built to face the internet, so exposure is the default, not a misconfiguration. And because it was attacked before anyone knew the flaw existed, applying the workaround today says nothing about what happened last week.
FortiMail indicators of compromise
Published by the vendor on October 1, 2026. Check every FortiMail appliance against this list before you change anything, because applying the workaround does not tell you whether someone already got in.
Source: vendor PSIRT advisory FG-IR-26-175, published October 1, 2026.
How to Avoid This
- Disable identity-based encryption with the three-line CLI command, or pull the management interface off the public internet and limit it to a trusted private network. Either one closes the door today.
- Treat every appliance between 7.2.0 and 8.0.1 as vulnerable until the vendor says otherwise.
- Hunt before you change anything. Preserve logs, configuration backups, and forensic images first, because a reboot or an upgrade can erase the evidence you need.
- Check your archive accounts and remote destinations by hand. An account nobody remembers creating is the loudest signal in the whole advisory.
- Then make the rule permanent. Management interfaces on security appliances don’t belong on the public internet, and that decision shouldn’t wait for the next advisory.