- Fortinet says attackers are exploiting CVE-2026-104286, a critical, no-login flaw in FortiMail's admin interface, scored 9.8 of 10. Fixes for three of four affected branches (7.4, 7.6, 8.0) are not yet released.
- Until patches arrive, Fortinet says to block Internet access to the management interface or limit it to trusted private networks, or disable the IBE feature using the advisory's commands.
- Check which FortiMail version you run, whether its admin panel faces the Internet, and search logs for the two IP addresses Fortinet published as signs of attack.
When a patch does not exist yet, the most important security control may not be software. For any appliance whose admin panel can be reached from the Internet, it is a network decision: who is allowed to get to that panel. The FortiMail zero-day makes that plain.
What Fortinet has said
Fortinet warned customers this week about CVE-2026-104286, a flaw in the management interface of its FortiMail email security product. Fortinet says it is being exploited in zero-day attacks. A zero-day is a flaw attackers use before a fix exists.
Fortinet scores the bug 9.8 on the 10-point CVSS severity scale, which puts it in the critical band. Its advisory says a remote attacker with no account could plant files of their choosing on the appliance's operating system. The attacker only has to send specially built web requests. "Unauthenticated" means no password is needed.
How the flaw works
Fortinet classes the bug under two weakness types. The first is path traversal (CWE-22). A web request is meant to touch only one folder, but crafted input lets it reach other parts of the system.
The second is improper handling of NULL characters (CWE-158). A NULL character is a special marker that can end a piece of text early. Fortinet does not spell out how the two combine. In general, such tricks can make a server misread where a file should go.
The result, per Fortinet, is that an outsider can write files onto the appliance. BleepingComputer reports the attacks aim to run unauthorized code or commands on the device.
Who is affected, and what is fixed
The flaw affects four FortiMail branches. They are versions 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8 and 7.2.0 to 7.2.9.
Three of those branches have no fix yet: 7.4, 7.6 and 8.0. Fortinet names versions 7.4.9, 7.6.7 and 8.0.2 as the coming releases that will contain the correction. Customers on 7.2 are told to move to the 7.4 branch or later. The source does not say which 7.4 build that means, so confirm it with Fortinet.
The workaround is a decision, not a download
Until patches ship, Fortinet says administrators can disable support for the IBE feature using commands in the advisory. The source does not explain what IBE is, so check what your teams use it for before switching it off.
Fortinet also offers an alternative: block Internet access to the management interface or limit it to trusted private networks. This may be the simpler option, since it does not touch a feature the business uses. It also raises a hard question: if your admin panel is reachable from the Internet, why?
That question lands on a person. An administrator now has to choose between a feature the business may rely on and a gap an attacker may use. That choice should be made by someone with authority to make it, not left to whoever sees the advisory first.
What the attackers' traces suggest
Fortinet also released indicators of compromise, meaning evidence that a system was attacked. Its advisory names files that appeared or changed on breached systems and includes example log events. It ties two IP addresses to the attacks, 79[.]141.169.187 and 45[.]129.0.192, which teams can search for in their own logs.
One log entry shows an archive account named archive234 being set up from the command line. Its remote server was 79.141.169.187 and its remote folder was /uploads. BleepingComputer notes this could mean the attacker told the appliance to send archived data to an outside server.
That is a reading of one log line, not a confirmed finding. But it may explain why attackers value a mail gateway, which handles mail by design.
What remains unknown
Three basic facts are still missing. Fortinet has not disclosed when attacks began, how many systems were breached, or who carried them out. It told BleepingComputer it is working with government bodies, including CISA.
CISA has added the flaw to its Known Exploited Vulnerabilities catalog. Federal agencies must complete forensic triage and mitigation by October 4. That deadline applies to federal agencies, not to private companies. It does signal how seriously CISA treats the flaw.
Questions to put to your team this week
Do we run FortiMail, and which version? Is its management interface reachable from the Internet? If so, who approved that, and can it be closed today?
Do we use the IBE feature, and who decides whether to disable it? Has anyone searched our logs for the published indicators? That means the two IP addresses, unfamiliar archive accounts, and cron jobs referencing /migadmin.
If a compromise is found, what mail data did the appliance hold? Your answer sets the scale of the response.
A patch fixes one flaw. A closed admin panel narrows the exposure for the next one as well.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: BleepingComputer.





