A critical flaw in Fortinet’s FortiMail email security gateway is already being used in real attacks, and the fix isn’t ready yet. CISA added the bug, tracked as CVE-2026-104286, to its Known Exploited Vulnerabilities (KEV) catalog on October 1, 2026, giving federal civilian agencies until October 4 to patch or mitigate it. With a CVSS score of 9.8 and no official patch available at publication time, the FortiMail zero-day is forcing security teams into a familiar, uncomfortable position: defend an internet-facing appliance against an unauthenticated attack with nothing but a workaround.
FortiMail sits at the edge of corporate email infrastructure, scanning and routing mail for thousands of organizations. That position is exactly what makes this bug dangerous, and exactly why Fortinet’s security history keeps repeating itself.
What CVE-2026-104286 Actually Does
CVE-2026-104286 combines two separate weaknesses: a path traversal flaw and an improper neutralization of NULL byte or NULL character issue, according to Help Net Security’s technical breakdown. Chained together, they let an unauthenticated attacker send crafted HTTP or HTTPS requests that bypass restrictions on file paths and write arbitrary files to the underlying FortiMail system. SecurityWeek reports that a successful write of the right file, in the right location, could escalate to arbitrary code or command execution on the appliance. The vulnerability is also catalogued in the National Vulnerability Database under its CVE identifier.
No authentication is required to attempt exploitation. That detail alone explains the urgency: any FortiMail appliance with its management interface reachable from the internet is a live target the moment a working exploit circulates. Path traversal bugs are common, but most require some foothold first. What makes this one critical is the combination: a network-reachable, pre-authentication entry point paired with a file-write primitive strong enough to plant a web shell or overwrite a configuration file.
That’s also why unauthenticated bugs tend to draw faster, broader scanning than credential-dependent flaws. An attacker doesn’t need a leaked password or a phished employee. They need only a reachable IP address and a crafted request, which is a far lower bar to clear at scale.
Which FortiMail Versions Are Exposed
The vulnerability spans four separate FortiMail branches, covering releases going back several years. Fortinet’s advisory, as relayed by both SecurityWeek and Help Net Security, lists the following affected ranges.
| FortiMail Branch | Affected Versions | Fix Status (as of Oct. 2, 2026) |
|---|---|---|
| 8.0 | 8.0.0 – 8.0.1 | Fix planned for 8.0.2 (not yet released) |
| 7.6 | 7.6.0 – 7.6.6 | Fix planned for 7.6.7 (not yet released) |
| 7.4 | 7.4.0 – 7.4.8 | Fix planned for 7.4.9 (not yet released) |
| 7.2 | 7.2.0 – 7.2.9 | No fix planned; move to 7.4 branch or later |
Notice the gap: every patched build listed above was described by both outlets as forthcoming, not downloadable, at the time of reporting. Admins running 7.2 get no patch path at all. Fortinet’s guidance for that branch is a full upgrade, not a point release.
Why CISA Set a Three-Day Remediation Clock
According to Security Affairs’ coverage of the CISA alert, the October 1 notice places CVE-2026-104286 under Binding Operational Directive 26-04, titled “Prioritizing Security Updates Based on Risk.” That directive instructs federal civilian agencies to move fastest on KEV entries tied to vulnerabilities that grant attackers full control of a publicly exposed asset after exploitation, which this one does. The result is a compressed window: a vulnerability added to KEV on Thursday carries a government-wide remediation deadline of Sunday, October 4.
Private-sector organizations aren’t bound by the directive, but security teams generally treat KEV deadlines as the realistic floor for how fast attackers will move, not the ceiling. If CISA judges three days reasonable for agencies running change-control processes and compliance reviews, a smaller IT team with direct admin access can often move faster, assuming the patch or workaround is actually ready to apply.
The pattern this year has been consistent, as shattered.io covered when CISA gave ScreenConnect customers three days to patch a CVSS 9.9 flaw and when Arista’s VeloCloud bug landed a matching three-day fix window. Three days has effectively become the default CISA response time for vulnerabilities that hand an attacker full post-exploitation control of an exposed asset, regardless of vendor or product category.
No Patch Yet: Fortinet’s Workaround, Explained
With fixed firmware still pending, Fortinet’s advisory points administrators toward two mitigations instead. The first is disabling Identity-Based Encryption (IBE) support on affected FortiMail instances, since the feature is tied to the vulnerable code path. The second, broader step is cutting off web-based access to the FortiMail management interface from the public internet entirely, restricting it to trusted internal networks only.
Neither mitigation removes the underlying flaw. Both reduce the attack surface until 8.0.2, 7.6.7, and 7.4.9 actually ship. Teams that cannot disable IBE because they depend on it operationally are left leaning entirely on network-level restriction, which only works if it’s enforced consistently across every exposed interface, not just the primary one.
Checking Your Own Exposure
Before anything else, administrators need to confirm which build they’re running. On Fortinet’s CLI, that’s a one-line check available on any FortiOS-based appliance, including FortiMail.
get system status
Pair that version check with a firewall-rule audit confirming the management interface isn’t reachable from outside the corporate network. If it is, and the firmware falls inside the affected ranges above, treat it as actively at risk rather than theoretically vulnerable.
Who Found It, and Who’s Exploiting It
Help Net Security credits Fortinet’s own Product Security team, including researcher Gwendal Guégniaud, with the internal discovery. German outlet Heise independently confirmed the active-exploitation warning and the workaround guidance for European readers. That’s a notable contrast with Fortinet’s prior SSL-VPN incidents, several of which only surfaced after outside researchers or active incident response engagements flagged exploitation already underway.
On the attacker side, the picture is thinner. No ransomware group or state-linked actor has been publicly named in connection with the exploitation CISA cited when it added CVE-2026-104286 to KEV. Fortinet’s advisory, according to SecurityWeek, confirms the flaw has been reported as exploited in the wild and urges customers to apply the workaround, without disclosing attacker identity or campaign scope. That absence of attribution doesn’t mean the activity is small. An unauthenticated file-write bug on an internet-facing mail gateway is exactly the kind of access that supports quiet persistence rather than loud, immediately obvious damage.
Email Gateways Keep Landing on the KEV List
Secure email gateways occupy an unusual spot in enterprise networks. They need broad internet exposure to do their job, scanning inbound mail from any sender, while also holding privileged access to route and modify traffic once it’s inside. That combination makes them attractive even when they aren’t the final target. A compromised mail gateway can read internal communications, inject malicious content into outbound mail, or serve as a pivot point deeper into the network.
It’s the same dynamic that made this year’s other edge-appliance bugs so disruptive, including the flaw behind Cisco’s CVSS 10.0 ISE zero-day and the issue patched in F5’s BIG-IP platform. Edge appliances sit exactly where attackers want to land: reachable from outside, trusted from inside.
Fortinet’s Pattern: Four Critical Zero-Days in Four Years
CVE-2026-104286 doesn’t stand alone. Fortinet’s SSL-VPN and gateway products have landed on CISA’s KEV catalog repeatedly since 2022, each time with a critical CVSS score and confirmed in-the-wild exploitation before a clean fix was widely deployed.
| CVE | Product / Flaw | CVSS | KEV Status |
|---|---|---|---|
| CVE-2022-42475 | FortiOS/FortiProxy SSL-VPN heap overflow, linked to the BOLDMOVE malware campaign | 9.8 | Added to KEV December 13, 2022 |
| CVE-2023-27997 | FortiOS/FortiProxy SSL-VPN heap overflow | 9.2 | Added to KEV June 13, 2023 |
| CVE-2024-21762 | FortiOS SSL-VPN out-of-bounds write | 9.6 | Confirmed exploited, added to KEV |
| CVE-2026-104286 | FortiMail path traversal / arbitrary file write | 9.8 | Added to KEV October 1, 2026 |
Every single entry in that table was flagged as actively exploited at or near the time of disclosure, not discovered quietly in a lab. That track record matters for how customers should weigh Fortinet’s security posture: the company’s edge products are consistently high-value targets, and attackers have repeatedly found working exploits before patches reached most of the install base.
The Wider 2026 Pattern: A Year of Compressed Deadlines
FortiMail’s three-day window isn’t an outlier in 2026, it’s the new baseline. Earlier this year, Citrix NetScaler customers blew past a similarly tight CISA deadline on a pair of CVSS 9.5 zero-days, and a JetBrains TeamCity flaw led to ransomware hitting roughly 160 servers before enough organizations patched. The table below lines up 2026’s run of critical, KEV-listed edge-appliance CVEs so far.
| Product | CVE / Flaw | CVSS | CISA Deadline Window |
|---|---|---|---|
| ScreenConnect | CVE-2026-84869 | 9.9 | 3 days |
| Citrix NetScaler | Two zero-days | 9.5 | Deadline passed before full remediation |
| Cisco ISE | CVE-2026-76460 | 10.0 | No workaround available |
| Arista VeloCloud | Zero-day | 10.0 | 3 days |
| F5 BIG-IP | CVE-2026-94127 | 9.8 | Short-window KEV deadline |
| JetBrains TeamCity | CVE-2026-63077 | 9.8 | Ransomware hit before patch adoption |
| Fortinet FortiMail | CVE-2026-104286 | 9.8 | 3 days (Oct. 1 – Oct. 4) |
Seven critical, actively exploited edge-appliance flaws in a single year, each carrying a near-maximum CVSS score, is a meaningful signal about where attackers are concentrating effort. Perimeter software, not endpoints, is where 2026’s highest-severity incidents keep originating.
The common thread across all seven cases isn’t a shared vendor or a shared codebase. It’s a shared role: every one of these products sits between the open internet and an organization’s internal network, handling traffic before any endpoint security tool gets a chance to inspect it. Endpoint detection and response platforms can’t see an exploit that never touches a laptop or a server inside the perimeter. That blind spot is exactly where FortiMail’s attackers, and the attackers behind the other six incidents, have been operating all year.
Market and Operational Impact
For Fortinet, the immediate impact is reputational rather than financial in any way that’s been disclosed. The company has not published revenue or customer-churn figures tied to this specific incident, and none should be assumed. What’s measurable is operational: every FortiMail customer now has to decide between disabling a feature they may rely on, locking down management access that some teams have left open for convenience, or accepting risk until patched firmware ships.
For competing secure email gateway vendors, including Proofpoint, Mimecast, Microsoft Defender for Office 365, and Cisco Secure Email, the incident is a sales opportunity dressed up as a cautionary tale. None of those products are immune to their own zero-days, but a high-profile, unauthenticated, actively exploited flaw in a rival’s flagship gateway is the kind of event competitive sales teams build outreach campaigns around.
There’s also a procurement angle that tends to get overlooked in the first 48 hours of a disclosure like this one. Enterprise security buyers who renew multi-year contracts don’t just react to the current incident, they factor it into the next vendor review cycle. A fourth critical, exploited zero-day since 2022 becomes a line item in that conversation, alongside uptime, support response times, and total cost of ownership. It won’t necessarily move existing FortiMail deployments off the platform overnight, since migrating a production email gateway is disruptive and expensive in its own right, but it does raise the bar Fortinet has to clear at the next contract renewal.
What Security Teams Should Do Right Now
- Confirm your FortiMail build number and check it against the affected ranges (8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, 7.2.0–7.2.9).
- Disable Identity-Based Encryption support if your organization doesn’t depend on it operationally.
- Remove public internet access to the FortiMail management interface, restricting it to trusted internal networks only.
- Watch for Fortinet’s 8.0.2, 7.6.7, and 7.4.9 releases and schedule patching the day they ship.
- If you’re on the 7.2 branch, begin planning the upgrade to 7.4 or later now rather than waiting on a point fix that isn’t coming.
- Review FortiMail logs for unexpected file writes or configuration changes predating today’s disclosure.
Predictions: Where This Goes From Here
A few trends look likely to play out over the coming weeks, based on how Fortinet’s previous KEV entries unfolded.
- Expect scanning activity to spike once proof-of-concept exploit code becomes public, mirroring the pattern seen after CVE-2022-42475 and CVE-2023-27997 disclosures.
- Patch adoption will likely lag the three-day federal deadline by weeks for many private-sector deployments, consistent with how slowly prior FortiOS SSL-VPN fixes propagated across the installed base.
- More FortiMail or FortiOS CVEs are plausible before year-end, given four critical, exploited zero-days have now landed across four consecutive years.
- Rival email security vendors will likely reference this incident in competitive positioning well into 2027.
- CISA’s three-day BOD 26-04 deadlines will keep tightening further for vulnerabilities granting full post-exploitation control, pressuring security teams with limited patch windows.
How FortiMail Compares to Rival Secure Email Gateways
FortiMail competes in a crowded secure email gateway market alongside Proofpoint, Mimecast, Microsoft Defender for Office 365, and Cisco Secure Email. All of these products share FortiMail’s core exposure problem to some degree: they need to process mail from untrusted senders by design, and several expose administrative interfaces that, if misconfigured, face the same kind of risk highlighted by CVE-2026-104286. The difference this week is that Fortinet is the vendor with a confirmed, unauthenticated, in-the-wild exploited flaw and no finished patch, while its direct competitors are not currently listed in CISA’s KEV catalog for an equivalent issue.
That doesn’t make rival products inherently more secure going forward. It does mean FortiMail customers evaluating whether to stay on the platform are weighing this incident against Fortinet’s broader track record of four KEV-listed, critical, exploited zero-days since 2022, a frequency that outpaces what’s been publicly reported for its closest direct competitors over the same period.
Historical Context: Why Fortinet Keeps Landing on KEV
Fortinet’s repeated appearances on CISA’s KEV catalog trace back to a structural reality: FortiOS-based products, including FortiGate firewalls and FortiMail gateways, share underlying code and sit at network edges by design. A flaw class that works against one FortiOS-based product family often has analogs elsewhere in the lineup. CVE-2022-42475’s heap overflow, CVE-2023-27997’s related SSL-VPN bug, and CVE-2024-21762’s out-of-bounds write all hit the same general product surface area even though the specific vulnerable code differed each time.
CVE-2026-104286 breaks that pattern slightly by hitting FortiMail’s own path-handling logic rather than the SSL-VPN stack, but the underlying lesson repeats: internet-facing Fortinet appliances remain a consistent, high-value target, and the company’s internal security team catching this one before full public disclosure is a modest improvement over past incidents where outside researchers found exploitation first.
Frequently Asked Questions
What is CVE-2026-104286?
It’s a critical path traversal and NULL byte handling flaw in Fortinet’s FortiMail email security gateway, carrying a CVSS score of 9.8. It allows an unauthenticated attacker to write arbitrary files to the system via crafted HTTP or HTTPS requests.
Is there a patch for CVE-2026-104286 yet?
Not at the time of this report. Fortinet has announced that fixes are planned for versions 8.0.2, 7.6.7, and 7.4.9, but neither SecurityWeek nor Help Net Security reported those builds as available for download yet. The 7.2 branch has no planned point fix and should move to 7.4 or later.
Which FortiMail versions are affected?
Versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9 are all listed as affected.
What is the CISA deadline for CVE-2026-104286?
CISA added the flaw to its KEV catalog on October 1, 2026, setting a remediation deadline of October 4, 2026 for federal civilian agencies under Binding Operational Directive 26-04.
How do I mitigate CVE-2026-104286 without a patch?
Fortinet recommends disabling Identity-Based Encryption (IBE) support where it isn’t required, and removing public internet access to the FortiMail management interface, limiting it to trusted internal networks only.
Was CVE-2026-104286 exploited before being publicly disclosed?
Yes. Fortinet’s advisory, as reported by SecurityWeek, confirms the flaw has already been exploited in the wild, which is why CISA fast-tracked it into the KEV catalog with a short remediation window.
Who discovered CVE-2026-104286?
Help Net Security credits Fortinet’s own Product Security team, including researcher Gwendal Guégniaud, with the internal discovery.
Has a specific ransomware group or hacking group been linked to the attacks?
No. As of this report, neither Fortinet nor CISA has publicly named a specific threat actor or ransomware group behind the observed exploitation.




