A critical zero-day vulnerability in Fortinet’s FortiMail email security platform is being actively exploited and this has prompted a warning from the US Cybersecurity and Infrastructure Security Agency (CISA).
Fortinet is a major cybersecurity provider used by organisations worldwide, while FortiMail protects enterprise email systems against threats including phishing, malware and business email compromise. The vulnerability therefore affects a security system designed to protect one of the most commonly targeted parts of an organisation’s infrastructure.
Tracked as CVE-2026-104286, the vulnerability has a CVSS score of 9.8 (out of a maximum of 10.0) and can allow an attacker to write files to a FortiMail system without first logging in or being authenticated - a serious security concern. Fortinet disclosed the flaw on 1 October, stating that it had been “reported to be exploited in the wild.”
The Hacker News reported on 2 October that CISA had added the vulnerability to its Known Exploited Vulnerability (KEV) catalogue. The KEV catalogue is an authoritative database keeping track of software and hardware security flaws that’ve been confirmed as actively exploited.
Why the FortiMail Vulnerability Matters
The vulnerability affects FortiMail’s management interface, which can be reached remotely through specially crafted web requests.
In simple terms, an attacker would not need a username, password or permission to access the system and exploit the flaw. If successful, the attacker can create or modify files on the affected FortiMail system, potentially giving them further access to the rest of the system to exploit for nefarious reasons
Fortinet has rated the vulnerability as critical, while Rapid7 also reports it can be exploited remotely without authentication or user interaction.
Fortinet credited Gwendal Guégniaud of its Product Security team with discovering and reporting the vulnerability.
FortiMail Versions Affected
Fortinet says the vulnerability affects several FortiMail versions:
| Branch | Affected versions | Fixed version |
| 8.0 | 8.0.0 – 8.0.1 | 8.0.2 or later |
| 7.6 | 7.6.0 – 7.6.6 | 7.6.7 or later |
| 7.4 | 7.4.0 – 7.4.8 | 7.4.9 or later |
| 7.2 | 7.2.0 – 7.2.9 | Upgrade to 7.4 or later |
Fortinet has already provided fixes for the 8.0, 7.6 and 7.4 branches and suggested temporary measures for those customers whose versions haven’t yet received an update or fix.
HKCERT, Hong Kong's cybersecurity incident response and coordination centre, has also classified the vulnerability as extremely high risk and directed users to Fortinet's security advisory.
Rethinking Patch Risk Windows
The Liquid exploit reveals how the gap between code changes and deployed patches becomes a critical risk as AI speeds exploit creation.
Fortinet Confirms Active Exploitation
Fortinet has confirmed that attackers are already exploiting the vulnerability, although the company hasn’t yet identified those behind the attacks or disclosed how many organisations have been affected.
The company has also provided indicators that organisations can use to check whether their FortiMail systems may have been compromised. These include two IP addresses linked to the attacks and several files that may have been added or modified on affected systems.
CISA Adds FortiMail Flaw to Warning List
CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalogue, immediately following reports of attackers using the flaw.
The catalogue is designed to highlight vulnerabilities that have already been exploited rather than simply identifying potential security weaknesses.
CISA has since set a 4 October 2026 remediation deadline for US federal agencies to address the vulnerability.
Fortinet Issues Temporary Mitigations
While updates and fixes are being released, Fortinet recommends two temporary measures: disabling FortiMail's Identity-Based Encryption (IBE) feature and/or restricting access between the FortiMail management interface and trusted private networks.
Fortinet has also provided indicators of compromise that organisations can use to check affected systems for signs of unauthorised activity.
The company will continue to investigate the attacks as organisations move to apply the available fixes and mitigations.
Comments ( 0 )