Critical FortiMail Flaw Exposed in Zero-Day Attacks, Urgent Patching Required
A critical vulnerability in FortiMail email security appliances has been exposed to zero-day attacks, with hackers exploiting the flaw to execute unauthorized code and commands on vulnerable devices. The affected versions of FortiMail include 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.
The vulnerability, tracked as CVE-2026-104286, is a Path Traversal and Improper Neutralization of NULL Byte or NULL Character flaw that can allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Fortinet’s Product Security team discovered the issue internally, and the company has warned customers that the flaw is being actively exploited.
The severity of this vulnerability cannot be overstated. With a CVSS score of 9.8, it ranks as one of the most critical security flaws in recent history. If left unpatched, FortiMail appliances can be compromised by hackers, who may use them to send malicious emails or conduct further attacks on the network.
To mitigate this risk, Fortinet is urging customers to apply shared workarounds until a security update can be installed. For affected users, patching the vulnerability requires upgrading to a newer version of FortiMail. Specifically, users running FortiMail 7.2 should upgrade to the 7.4 branch or later, while those on FortiMail 7.4, 7.6, and 8.0 can expect security updates in upcoming versions – including FortiMail 7.4.9, 7.6.7, and 8.0.2.
In the meantime, administrators can take a few steps to protect their systems. Disabling IBE feature support using specific commands is one temporary workaround. Alternatively, admins can disable access to the FortiMail management interface from the Internet or restrict access to trusted private networks. Fortinet has also published indicators of compromise (IOCs) associated with the attacks, including several files that were added or modified on compromised systems.
The IOCs provide valuable information for administrators looking to identify potentially compromised appliances. For example, log entries may show an archive account being configured from the command line with a remote server and directory, indicating that the attacker configured the compromised FortiMail appliance to send archived data to a remote server.
In light of this critical vulnerability, it is essential for all FortiMail administrators to take immediate action. Regularly review your system logs for suspicious activity, ensure you are running the latest version of FortiMail, and implement additional security measures to prevent unauthorized access.
Source: Bleeping Computer — 2026-10-01