Fortinet Sounds Alarm on Critical FortiMail Zero-Day Under Active Attack
Fortinet is warning customers about a critical vulnerability in FortiMail, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks. The flaw, which scores 9.8 on the CVSS scale, allows an unauthenticated attacker to write arbitrary files on the underlying system through crafted HTTP or HTTPS requests, potentially enabling unauthorized code execution on vulnerable devices.
The vulnerability affects FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet's Product Security team discovered the flaw internally. Fixes are not yet available for the 7.4, 7.6, and 8.0 branches, with patched versions 7.4.9, 7.6.7, and 8.0.2 listed as upcoming. Users running FortiMail 7.2 can address the issue by upgrading to the 7.4 branch or later.
Until patches arrive, Fortinet urges admins to disable IBE feature support via the system encryption configuration or to restrict access to the FortiMail management interface by blocking internet access or limiting it to trusted private networks. The company has also published indicators of compromise, including SHA-256 hashes for files added or modified on compromised systems such as liblog.so, webconsole, and mailservice, so defenders can check for signs of exploitation.