Critical FortiMail Zero-Day Under Active Attack: CISA Gives Federal Agencies Three Days to Patch
Critical FortiMail Zero-Day Under Active Attack: CISA Gives Federal Agencies Three Days to Patch
A newly disclosed vulnerability in Fortinet's FortiMail email security platform has prompted urgent action across the cybersecurity industry. The flaw, tracked as CVE-2026-104286, carries a near-maximum CVSS severity score of 9.8 and is reportedly being exploited by attackers before most organizations have had a chance to patch. Many observers note that the combination of a critical severity rating, unauthenticated exploitation, and confirmed real-world attacks makes this one of the more pressing enterprise security issues of the year.
Critical FortiMail Zero-Day Under Active Attack
Fortinet's security advisory explains that CVE-2026-104286 allows unauthenticated attackers to write arbitrary files to vulnerable FortiMail systems. The technique reportedly relies on path traversal combined with NULL byte injection inside specially crafted HTTP or HTTPS requests. Because the flaw does not require authentication, any internet-exposed and vulnerable FortiMail instance could, in theory, be targeted directly.
Fortinet has confirmed that the vulnerability has already been exploited in the wild, a detail that elevates the issue from a theoretical risk to an active, ongoing concern for organizations running affected systems. The vulnerability was discovered internally by Gwendal Guégniaud of Fortinet's Product Security team, and the company has published a dedicated advisory under the identifier FG-IR-26-175.
CISA's Three-Day Remediation Deadline
The Cybersecurity and Infrastructure Security Agency, known as CISA, added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1, 2026. Under the authority of Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies have been directed to remediate the vulnerability by October 4, 2026 — a notably compressed window that reflects both the severity of the flaw and confirmation that it is already being exploited.
While the KEV directive is formally binding only on federal agencies, security researchers and industry commentators have widely encouraged private-sector organizations running FortiMail to treat the same deadline as a practical benchmark, given the shared urgency of the threat.
Which Versions Are Affected
Fortinet's advisory lists several affected version branches, spanning a wide swath of FortiMail deployments currently in use:
- FortiMail 7.2.0 through 7.2.9
- FortiMail 7.4.0 through 7.4.8
- FortiMail 7.6.0 through 7.6.6
- FortiMail 8.0.0 through 8.0.1
Fortinet has released fixed versions for most of these branches, including FortiMail 8.0.2, 7.6.7, and 7.4.9. Notably, the older 7.2.x branch does not have a direct patch available; organizations running this branch are instead advised to migrate to a supported, fixed version rather than wait for a backported fix.
A recurring concern raised by security teams is that FortiMail management interfaces are sometimes left exposed to the internet, which would meaningfully increase the attack surface for this particular vulnerability.
Signs of Compromise and What's Still Unknown
Fortinet has published indicators of compromise associated with observed exploitation attempts, including specific IP addresses and file paths. According to the advisory, these indicators show patterns of file additions and modifications consistent with attackers attempting to establish persistent, backdoor-like access to compromised systems.
Several important details remain undisclosed as of this writing. Fortinet and CISA have not published the total number of compromised appliances worldwide, nor has either organization attributed the exploitation activity to a specific threat actor or group. The exact start date of the exploitation campaign has also not been made public. Security researchers tracking the issue have cautioned that the full scope of impact may not be clear for some time.
What Organizations Should Do Now
Security teams and IT administrators responsible for FortiMail deployments are encouraged to take the following steps:
- Apply the available patched versions — 8.0.2, 7.6.7, or 7.4.9 — as soon as possible.
- Organizations still running the 7.2.x branch should prioritize migration to a supported, fixed version rather than waiting for a direct patch.
- Review systems against the indicators of compromise published by Fortinet to check for signs of prior compromise.
- As an interim mitigation, restrict or closely monitor internet exposure of FortiMail management interfaces.
Given the confirmed in-the-wild exploitation and the short remediation window set by CISA, security professionals broadly agree that organizations running affected FortiMail versions should treat this as a high-priority action item rather than a routine patch cycle.