FortiMail Operators Face Active Exploitation While Fixes Remain Upcoming
FortiMail faces active exploitation. CVE-2026-104286 allows unauthenticated arbitrary-file writes through crafted HTTP or HTTPS requests. Fortinet assigns CVSS 9.8.
Update, 2 October: Fortinet changed containment; its record omits file indicators.
Choose the right branch
Fortinet’s 1 October guidance:
- 8.0.0-8.0.1: upcoming 8.0.2 or later
- 7.6.0-7.6.6: upcoming 7.6.7 or later
- 7.4.0-7.4.8: upcoming 7.4.9 or later
- 7.2.0-7.2.9: migrate to a currently unaffected later branch
Upcoming is the vendor’s label, not verified availability. The 7.2 migration must avoid affected 7.4.0-7.4.8.
Contain the exposure
Disable IBE feature support:
config system encryption ibe
set status disable
end
Alternatively, restrict webmail to trusted private networks or have a fronting WAF block POST /ibe requests containing ../. The advisory does not establish IBE enablement as an exploit prerequisite.
The official record now lists IP and log indicators. Missing indicators are not an all-clear.
Keep containment and investigation connected
CISA’s forensic guidance sets out a useful sequence: scope the assets, preserve relevant evidence before changes where possible, then mitigate and analyse. Escalate credible compromise findings rather than closing the incident at the first successful change.
Record the owner, exposure, evidence retained and unresolved questions under CVE-2026-104286. A mitigation ticket and an investigation ticket must not report contradictory states. Separate a completed action from a verified outcome.
BlackTree’s earlier FortiGate pivot report covers a different incident. Its operational lesson remains relevant: closing a route does not establish that earlier access caused no harm.
Read the deadline correctly
CISA added this vulnerability to KEV on 1 October, with a 4 October due date and forensic triage required. BOD 26-04 applies to in-scope US Federal Civilian Executive Branch systems using exposure-dependent timelines. Agencies must determine the applicable deadline for each asset. The catalogue date is not a universal legal deadline for other organisations.
Sources
- Fortinet advisory, published 1 October and revised 2 October 2026; official CSAF.
- CISA KEV, catalogue 2026.10.01.
- BOD 26-04 and implementation guidance.


