← All news
Vulnerability ManagementThreat IntelligenceIncident Response

Fortinet Confirms a Critical FortiMail Zero-Day Is Already Being Exploited, and the Patches Are Still Not Out

Obiguard Research Team·October 4, 2026·4 min read

Fortinet has confirmed that attackers are exploiting a critical zero-day in FortiMail, its email security appliance, and fixed releases are not yet available. The flaw, CVE-2026-104286, carries a CVSS score of 9.8, and CISA has added it to its Known Exploited Vulnerabilities catalog, according to CyberInsider's report.

What the vulnerability is

CVE-2026-104286 is a path traversal flaw combined with improper handling of NULL bytes in the FortiMail web management interface. An unauthenticated attacker can send crafted HTTP or HTTPS requests and write arbitrary files to the underlying system. File write on an appliance that processes an organisation's email is a short step from persistent code execution.

Who is affected

Per the report, the following releases are affected:

  • FortiMail 8.0.0 to 8.0.1
  • FortiMail 7.6.0 to 7.6.6
  • FortiMail 7.4.0 to 7.4.8
  • FortiMail 7.2.0 to 7.2.9

Fortinet is preparing fixes in 8.0.2, 7.6.7 and 7.4.9. Customers on 7.2 are advised to move to 7.4 or later, as there is no 7.2 fix.

Exploitation is confirmed

Fortinet reported in-the-wild attacks as of 1 October 2026 and published indicators of compromise, including the IP addresses 79.141.169[.]187 and 45.129.0[.]192 and a list of modified files such as /data/lib/liblog.so and /data/bin/webconsole. The attacker has not been identified, and Fortinet has not said how many customers were compromised. CISA's deadline for US federal civilian agencies to apply mitigations or patches is 4 October 2026.

What to do before the patch arrives

Fortinet's interim guidance is short:

  1. Disable Identity-Based Encryption (IBE) support if you do not depend on it.
  2. Restrict the management interface to trusted private networks. It should not be reachable from the internet.
  3. Check your exposure. Find every FortiMail appliance, including ones in branch offices and test environments, and confirm its version.
  4. Hunt for the indicators. Search for the published IP addresses in web and firewall logs and compare the listed binaries against known-good hashes. Treat any mismatch as a compromise and start incident response rather than waiting for a patch.

The pattern behind it

This is the second time in a week that a security or edge product has been the entry point. Bitget's $388 million loss also began with a zero-day in a third-party security tool. Appliances like mail gateways, VPNs and SD-WAN managers sit at the network boundary, hold privileged access, and often cannot run an endpoint agent. They are patched slowly and watched poorly, which is why attackers keep choosing them.

The practical lesson is about the window between disclosure and a fix. For FortiMail, that window is open now. During it, the only defences are exposure reduction and detection.

Where Obiguard SOC fits

Obiguard SOC is built for that window. It matches the vulnerabilities in your environment against CISA's KEV catalog through its CVE Radar, so an appliance affected by a newly listed flaw like this one surfaces as a severity-scored alert instead of an advisory somebody has to remember to check. Its log and metrics observability gives you a place to search for indicators such as Fortinet's IP addresses and unexpected configuration changes, and to see unusual outbound traffic from a device that should only be handling mail.

None of this replaces Fortinet's patch. It shortens the time between "a flaw was exploited somewhere" and "we know whether it affects us, and whether we have been touched."

The question to take away

If Fortinet's indicators were published to your team this morning, could you tell within the hour which appliances you run, whether each is exposed, and whether any of them has been contacted by those addresses?

See how Obiguard SOC works or talk to us about keeping watch on the systems you cannot patch yet.

How Obiguard helps

Turn this into enforced policy, not just awareness.

Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.

See how it works →