Fortinet has confirmed that attackers are exploiting a critical zero-day in FortiMail, its email security appliance, and fixed releases are not yet available. The flaw, CVE-2026-104286, carries a CVSS score of 9.8, and CISA has added it to its Known Exploited Vulnerabilities catalog, according to CyberInsider's report.
CVE-2026-104286 is a path traversal flaw combined with improper handling of NULL bytes in the FortiMail web management interface. An unauthenticated attacker can send crafted HTTP or HTTPS requests and write arbitrary files to the underlying system. File write on an appliance that processes an organisation's email is a short step from persistent code execution.
Per the report, the following releases are affected:
Fortinet is preparing fixes in 8.0.2, 7.6.7 and 7.4.9. Customers on 7.2 are advised to move to 7.4 or later, as there is no 7.2 fix.
Fortinet reported in-the-wild attacks as of 1 October 2026 and published indicators of compromise, including the IP addresses 79.141.169[.]187 and 45.129.0[.]192 and a list of modified files such as /data/lib/liblog.so and /data/bin/webconsole. The attacker has not been identified, and Fortinet has not said how many customers were compromised. CISA's deadline for US federal civilian agencies to apply mitigations or patches is 4 October 2026.
Fortinet's interim guidance is short:
This is the second time in a week that a security or edge product has been the entry point. Bitget's $388 million loss also began with a zero-day in a third-party security tool. Appliances like mail gateways, VPNs and SD-WAN managers sit at the network boundary, hold privileged access, and often cannot run an endpoint agent. They are patched slowly and watched poorly, which is why attackers keep choosing them.
The practical lesson is about the window between disclosure and a fix. For FortiMail, that window is open now. During it, the only defences are exposure reduction and detection.
Obiguard SOC is built for that window. It matches the vulnerabilities in your environment against CISA's KEV catalog through its CVE Radar, so an appliance affected by a newly listed flaw like this one surfaces as a severity-scored alert instead of an advisory somebody has to remember to check. Its log and metrics observability gives you a place to search for indicators such as Fortinet's IP addresses and unexpected configuration changes, and to see unusual outbound traffic from a device that should only be handling mail.
None of this replaces Fortinet's patch. It shortens the time between "a flaw was exploited somewhere" and "we know whether it affects us, and whether we have been touched."
If Fortinet's indicators were published to your team this morning, could you tell within the hour which appliances you run, whether each is exposed, and whether any of them has been contacted by those addresses?
See how Obiguard SOC works or talk to us about keeping watch on the systems you cannot patch yet.
Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.
See how it works →