preloader

· · digital-security cve fortinet fortimail email-security cisa-kev patch-management vulnerability-management europe

Fortinet FortiMail Zero-Day Is Under Active Attack, and There Is No Patch Yet

Source: SecurityWeek

Email security appliances are having a brutal season, and the newest example is unusually urgent. Fortinet and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have sounded the alarm on CVE-2026-104286, a critical vulnerability in FortiMail with a CVSS score of 9.8 that is already being exploited in the wild. What sets this one apart from the usual zero-day cycle: there is no patch available yet, only a workaround.

What the flaw does

The vulnerability combines path traversal with improper neutralization of NULL bytes, and it allows an unauthenticated attacker to write arbitrary files to the underlying system using crafted HTTP or HTTPS requests. In practice, that can escalate to arbitrary code or command execution on the appliance itself. Fortinet says the bug was discovered internally and affects FortiMail 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1. Fixes are planned for versions 7.4.9, 7.6.7 and 8.0.2, but no release timeline has been given.

CISA is already watching, and the clock is short

CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 2, with federal agencies required to remediate within three days under Binding Operational Directive 26-04. Even if your organisation is not a U.S. federal agency, KEV inclusion is a reliable signal that attackers are using this flaw right now. Fortinet recommends disabling IBE feature support or restricting access to the FortiMail management interface to trusted sources only, and the company has published indicators of compromise so security teams can hunt for signs of intrusion.

Why European teams should not wait for the patch

For European organisations, a mail gateway is one of the worst possible places to lose control, because the appliance sits on the path of every inbound and outbound message, often including the credentials and metadata that flow with them. With no patch to install, the response has to be compensating controls: apply the workaround, verify management interface exposure, review logs against the published indicators, and confirm that your recovery plan for the appliance is current rather than theoretical.

If you run FortiMail and want a fast, independent check of your exposure, including whether your instance is reachable and whether the workaround has been applied correctly, contact Excello Digital. We help European companies respond to active exploitation before it becomes an incident.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!