Active Exploitation of Vulnerability in Fortinet FortMail
6 October 2026
Attackers are exploiting a critical vulnerability in Fortinet FortiMail to write arbitrary files on the underlying system. Patch immediately.
Background
Fortinet has released security updates to address a critical vulnerability (CVE-2026-104286) affecting Fortinet FortiMail. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 9.8 out of 10.
Impact
Due to an improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiMail, an unauthenticated attacker could write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Known Exploitation
This vulnerability is reportedly being actively exploited.
Affected Products
The vulnerability affects the following products:
Fortinet FortiMail versions 7.2.0 through 7.4.8
Fortinet FortiMail versions 7.6.0 through 7.6.6
Fortinet FortiMail versions 8.0.0 through 8.0.1
Users and administrators should refer to the vendor advisory for the full list of affected versions.
Recommendations
Users and administrators of affected products are advised to implement Fortinet's workarounds and update to the latest versions once these are available.
Organisations are also encouraged to scan their Fortinet FortiMail deployments to check for Indicators of Compromise (IOCs).
Fortinet's workarounds and known IOCs are available at https://fortiguard.fortinet.com/psirt/FG-IR-26-175 (opens in new tab)
References
