Back to Blog

An Unauthenticated Attacker Can Write Files to Your Email Security Box. One HTTP Request. No Patch for Most Versions.

CVE-2026-104286 appeared in Fortinet’s security advisories last week without generating much mainstream coverage.[1] The vulnerability is in FortiMail, the email security appliance that a lot of mid-size businesses and MSPs run to filter spam, block malware attachments, and handle encrypted email delivery. CVSS score: 9.8. Status: actively exploited. Patch availability: still pending for most affected versions.

The attack is about as simple as these get. An unauthenticated attacker sends a single crafted HTTP or HTTPS request to your FortiMail appliance and writes an arbitrary file anywhere on the system. No credentials. No phishing. No foothold required first. Just the request.

CISA added it to their Known Exploited Vulnerabilities catalog and gave federal agencies until October 4 to apply a workaround. That deadline was yesterday. The workaround exists. The full patch does not, for most branches.

What FortiMail Is and Why This Matters to Small Businesses

FortiMail is Fortinet’s dedicated email gateway. It sits in front of your mail server and handles inbound and outbound filtering, spam blocking, malware scanning, and Identity-Based Encryption (IBE), which lets you deliver encrypted email to recipients without requiring them to install software on their end. It’s common in the 20-to-200-employee business range, often deployed by MSPs as part of a Fortinet-heavy security stack.

If you’re a small or mid-size business and your IT setup involves Fortinet products, there’s a real chance FortiMail is in your environment, even if you don’t interact with it directly. Your MSP or internal IT team would know for sure.

Affected versions cover a wide range: FortiMail 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1.[2] If you’re on any of those, the vulnerability applies to you.

How the Exploit Actually Works

Two bugs combine to make this possible. The first is a path traversal flaw. The software fails to properly restrict file paths in incoming requests, which means an attacker can specify a path that escapes the intended directory.[3] The second is a NULL byte handling problem. Together they let an attacker write a file to an arbitrary location on the underlying system, not just inside FortiMail’s own directories.

Fortinet confirmed active exploitation in the wild when they published the advisory.[1] They haven’t disclosed who is behind the attacks or what the attackers are writing to the affected systems, which is pretty typical at the early stages of an investigation. What an attacker can do once they’ve written arbitrary files to your email gateway is a long list: plant a webshell, replace a configuration file, drop persistence mechanisms. None of it is good.

The attack surface is any FortiMail appliance with a management interface reachable from the internet. Fortinet’s default configuration exposes that interface, and plenty of deployments leave it that way.

The Workaround (and the Tradeoff)

Fortinet’s official workaround is to disable the IBE feature through the CLI:[4]

config system encryption ibe
    set status disable
end

The path traversal exploit runs through code the IBE feature uses, so disabling IBE closes the vulnerable code path. It’s not a patch, but it blocks the known attack vector. Fortinet also recommends cutting off public internet access to the management interface entirely, restricting it to trusted private networks only. That second step should have been done regardless of this vulnerability.

The tradeoff: if your organization uses IBE to deliver encrypted emails to external recipients, that capability goes dark until you upgrade to a fixed release. The fixed versions will be FortiMail 7.4.9, 7.6.7, and 8.0.2.[2] Those aren’t released yet for most branches as of today. Watch Fortinet’s PSIRT advisory for when they drop, and schedule the upgrade promptly.

Given a 9.8 severity and confirmed active exploitation, applying the workaround and accepting the IBE downtime is the right call.

What to Do Right Now

First, confirm whether you’re running FortiMail. If you manage your own IT, check your network hardware inventory. If you use an MSP, ask them directly. “Are we running FortiMail, and have you applied the CVE-2026-104286 workaround?” is a completely reasonable question to ask today.

If you are running an affected version, apply the IBE workaround via the CLI. Restrict management interface access to trusted internal IP ranges. Document the change. Then watch for the patched releases and plan the upgrade.

One more thing worth saying while we’re here: Fortinet has had a busy year for disclosed vulnerabilities. The FortiBleed credential leak campaign in June, the Cisco ASA comparison last August, and now this. I’m not saying don’t use Fortinet, because they make solid products and patch things when they find them. But if you run a Fortinet-heavy environment, you need someone actively watching their PSIRT feed, not just patching when something comes up in the news.

Most small businesses I talk to aren’t doing that. It’s not a criticism, it’s just a gap that tends to close only after something goes wrong.

If you’re not sure whether FortiMail is in your environment, or if you want a second set of eyes on whether your Fortinet gear is current on patches and configured correctly, reach out here or call us at (412) 307-8313. We work with a lot of Pittsburgh businesses running Fortinet stacks and we know where the exposure points tend to be.

Share
  1. The Hacker News, “Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes,” October 2026, thehackernews.com
  2. Field Effect, “Patches pending for actively exploited FortiMail flaw,” October 2026, fieldeffect.com
  3. The Cyber Sec Guru, “CVE-2026-104286: FortiMail Zero-Day Actively Exploited,” October 2026, thecybersecguru.com
  4. Tech Insider, “FortiMail Zero-Day CVE-2026-104286: CVSS 9.8, CISA Deadline,” October 2026, tech-insider.org