DKDKCISSPSearch
VulnerabilitiesDEVELOPING

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net Security

Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway.

DKCISSP News DeskHelp Net Security2 Oct 2026, 2:20 pm
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net Security
Image courtesy of Help Net Security. Original report
DKCISSP REPORT

Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway.

Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available.

the company said in a security advisory published on October 1, 2026.

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog the same day, and gave US federal civilian agencies until October 4, 2026, to address it.

The vulnerability, with a CVSSv3 score of 9.8, was discovered internally by Gwendal Guégniaud of the company’s Product Security team.

Fortinet will fix it in versions 8.0.2, 7.6.7 and 7.4.9, which have not been released, and advises 7.2 users to upgrade to the 7.4 branch or above.

Until the patch is available, customers can disable support for IBE, FortiMail’s identity-based encryption feature, with these CLI commands: Alternatively, administrators can block internet access to the management interface or restrict it to a trusted private network.

Fortinet did not share details about when or where the attacks were spotted, how many systems were compromised, or who was behind them.

Fortinet’s researchers have also shared the files, IP addresses and log entries tied to the attacks so that administrators can check whether their FortiMail appliances have been compromised.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.

The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system.

Fortinet has acknowledged that the vulnerability has been exploited in the wild, urging customers to apply the following workarounds until fixes are available for certain versions - Fortinet credited Gwendal Guégniaud of the Fortinet Product Security team with discovering and reporting the flaw.

It has shared the following indicators of compromise - In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the patch or workarounds by October 4, 2026.

The development comes as number of security flaws in Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) have come under in-the-wild exploitation.

What happened

Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway.

Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available.

the company said in a security advisory published on October 1, 2026.

What changed

The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog the same day, and gave US federal civilian agencies until October 4, 2026, to address it.

The vulnerability, with a CVSSv3 score of 9.8, was discovered internally by Gwendal Guégniaud of the company’s Product Security team.

Fortinet will fix it in versions 8.0.2, 7.6.7 and 7.4.9, which have not been released, and advises 7.2 users to upgrade to the 7.4 branch or above.

Who is affected

Until the patch is available, customers can disable support for IBE, FortiMail’s identity-based encryption feature, with these CLI commands: Alternatively, administrators can block internet access to the management interface or restrict it to a trusted private network.

Fortinet did not share details about when or where the attacks were spotted, how many systems were compromised, or who was behind them.

Why it matters

Fortinet’s researchers have also shared the files, IP addresses and log entries tied to the attacks so that administrators can check whether their FortiMail appliances have been compromised.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.

Technical details

The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system.

Fortinet has acknowledged that the vulnerability has been exploited in the wild, urging customers to apply the following workarounds until fixes are available for certain versions - Fortinet credited Gwendal Guégniaud of the Fortinet Product Security team with discovering and reporting the flaw.

It has shared the following indicators of compromise - In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the patch or workarounds by October 4, 2026.

Response

The development comes as number of security flaws in Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) have come under in-the-wild exploitation.

Fortinet says the flaw is being actively exploited and is urging customers to apply the shared workarounds until a security update can be installed.

What security teams should do

FortiMail 7.2 users can patch the vulnerability by upgrading to the 7.4 branch or later.

For affected FortiMail 7.4, 7.6, and 8.0 installations, security updates are not yet available, with Fortinet listing FortiMail 7.4.9, 7.6.7, and 8.0.2 as upcoming versions containing the fix.

What remains unknown

Fortinet has not disclosed when the flaw was first exploited, how many systems were compromised, or who is behind the attacks.

Cisco recommends reviewing the following logs for requests related to j_security_check from unknown or unauthorized IP addresses: /var/log/nms/containers/service-proxy/serviceproxy-access.log : Requests with an encoded character in the j_security_check path, such as POST /%6a_security_check HTTP/1.1 .

It also advised security teams investigating potentially compromised SD-WAN systems to check the serviceproxy-access.log file located under /var/log/nms/containers/service-proxy and the vmanage-server.log file under /var/log/nms/ for entries related to j_security_check from unknown or unauthorized IP addresses.

Attribution

Help Net Security: Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway.

The Hacker News: The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.

BleepingComputer: Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.

SC Media: The Cybersecurity and Infrastructure Security Agency (CISA) added a critical CVSS 9.8 authentication bypass flaw in Cisco Catalyst SD-WAN Manager to its known exploited vulnerabilities (KEV) catalog on Sept. 30.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN VULNERABILITIES

More cybersecurity reporting

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmFortinet warns of critical FortiMail flaw exploited in zero-day attacksBleepingComputer · 2 Oct 2026, 4:12 am