Fortinet has disclosed a critical vulnerability in FortiMail, its email security gateway, and says it has been reported to be exploited in the wild. If your business runs a FortiMail appliance or virtual machine to filter email, upgrade now, or switch off the affected feature until you can. CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1, 2026, with an action due date of October 4, 2026.
Note: CISA’s due date for this flaw in its Known Exploited Vulnerabilities catalog was October 4, 2026. If your FortiMail is not upgraded and IBE is still on, do it now.
What happened
The flaw is tracked as CVE-2026-104286 and in Fortinet’s advisory FG-IR-26-175, both published October 1, 2026. Fortinet describes it as a path traversal problem (an “improper limitation of a pathname to a restricted directory”) that “may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.” CISA’s catalog entry adds that it also involves improper handling of NULL bytes.
In plain terms, someone on the internet who can reach the FortiMail web interface can write files onto the device without signing in. Fortinet lists the impact as “execute unauthorized code or commands.” Fortinet scores it 9.8 out of 10 (critical) on the CVSS scale, and that is the score NVD shows.
Fortinet’s advisory is direct: “This has been reported to be exploited in the wild, customers are urged to apply the workaround below.” Fortinet’s own product security team found the flaw.
Who is affected
Fortinet’s advisory lists these FortiMail versions as affected, with these fixes:
- FortiMail 8.0.0 through 8.0.1: upgrade to 8.0.2 or above.
- FortiMail 7.6.0 through 7.6.6: upgrade to 7.6.7 or above.
- FortiMail 7.4.0 through 7.4.8: upgrade to 7.4.9 or above.
- FortiMail 7.2.0 through 7.2.9: there is no 7.2 fix. Fortinet’s instruction is to move to the 7.4 branch or later.
One detail matters if you run an older box. The affected-product list Fortinet supplied to the National Vulnerability Database (NVD) also includes FortiMail 7.0.0 through 7.0.9. NVD’s own analysis of affected configurations starts at 7.2.0, and Fortinet’s advisory does not mention 7.0 at all. If you are on 7.0, assume you are affected. Ask Fortinet or your reseller for a supported upgrade path in writing.
This is about FortiMail specifically. It does not apply to FortiGate firewalls or other Fortinet products unless Fortinet says so. If you are not sure what filters your email, look at your domain’s mail (MX) records or ask whoever set it up. If a provider runs FortiMail for you, ask them now whether it has been upgraded or mitigated.
What to do now
Forward this list to whoever manages your email gateway. Do steps 1 through 4 first; they should not wait.
- Confirm the version. Sign in to the FortiMail admin console and note the firmware version. Compare it to the list above.
- Upgrade if you can. Move to 8.0.2, 7.6.7 or 7.4.9 or later, depending on your branch. If you are on 7.2 (or 7.0), plan the move to 7.4 or later, and use the workaround in the meantime.
- If you cannot upgrade right away, turn off IBE. This is the workaround Fortinet urges. In the web console, go to Encryption, then IBE, and set IBE Service to off. From the command line: config system encryption ibe, then set status disable, then end. If your business sends encrypted email to customers through FortiMail, that stops working while IBE is off. Tell staff before you flip it.
- Close the door from the internet. Fortinet also lists two other mitigations. Restrict FortiMail webmail so it is reachable only from trusted private networks, not the open internet. Or put a web application firewall in front of it that blocks POST requests to /ibe containing ../.
- Look for signs it already happened. Fortinet published indicators of compromise. Check your logs for connections from 79.141.169.187 or 45.129.0.192. In the system event logs, look for suspicious cron commands, unexpected admin logouts, or an archive account set to send to the remote IP 79.141.169.187 with the remote directory /uploads. In the encryption logs, look for “Invalid Base64 Encoding” errors and failed internal user sign-ins.
- If you find any of those, treat it as an incident. Do not just patch and move on. An attacker who could write files may have left something behind. Preserve the logs, change the FortiMail admin credentials, and get help investigating before you trust the device again. CISA’s catalog entry points to its forensics triage guidance for this situation.
- Write down what you did and when. Note the version before and after, the time of the change, and what you checked. Your cyber insurer, an auditor or a prime contractor may ask later.
What about the October 4 deadline?
CISA’s catalog entry sets an action due date of October 4, 2026, under its directive BOD 26-04. That directive applies to Federal Civilian Executive Branch systems and the agencies operating them. CISA notes that contractors are generally not covered unless their contracts require compliance. For most private businesses, then, October 4 is not a legal deadline. It is still a sensible target, because the flaw is already being exploited.
If you are a defense contractor, check your contracts and flow-down clauses rather than assuming either way.
What can wait
- Replacing FortiMail. A serious flaw is not, on its own, a reason to rip out your email gateway. Patch now and judge the product later, when you are not under pressure.
- Re-enabling IBE. If you turned IBE off as a stopgap, turn it back on only after you are on a fixed version.
- A broader review of what faces the internet. This is a good prompt to list every device with a web console reachable from outside: email gateways, VPNs, firewalls, remote access tools. That inventory is worth doing once steps 1 through 4 are done.
When to get help
Get help if any of these apply: you are on 7.0 or 7.2 and need a branch upgrade, you found any of the indicators above, you rely on IBE for encrypted customer email and cannot turn it off, or nobody on your team knows the FortiMail admin password. A branch upgrade on the device that handles all your mail is worth planning carefully. An investigation also goes better when the logs are preserved first.
Our engineers can check your exposure, apply the fix or workaround, and review the logs with you. For a broader look at how your email is protected, see our email security check. If you would like a hand with FortiMail, contact Summit Networks.

Leave a Reply