Security
FortiMail's Exploited Zero-Day Has a Sunday Deadline and No Shipped Patch. Compliance Means Switching Features Off
Fortinet disclosed CVE-2026-104286, an unauthenticated 9.8-rated flaw in FortiMail already exploited in the wild, and CISA set an October 4 federal deadline the same day. The fixed builds had not shipped, so the only levers before Sunday are turning Identity-Based Encryption off and taking the management interface off the internet.
MAI
Fortinet published advisory FG-IR-26-175 on October 1 and CISA added the vulnerability it describes to the Known Exploited Vulnerabilities catalog the same day, with a remediation deadline of October 4 for US federal civilian agencies. That is a three-day clock, over a weekend, for a flaw rated 9.8 that an unauthenticated attacker can reach over HTTP. The complication is the one that makes this worth writing about: the builds Fortinet names as fixed had not shipped when the advisory went up. Anyone inside that deadline has to meet it by removing function, not by patching.
What the advisory says
CVE-2026-104286 is a path traversal in FortiMail combined with improper handling of null bytes. In Fortinet's words, it allows an attacker to "write arbitrary files on the underlying system via crafted HTTP or HTTPS requests" — with no credentials. Fortinet states exploitation in the wild. The credit in the advisory goes to Fortinet's own product security team, which means the company found the bug itself and found it already in use.
| Branch | Affected | Fortinet's fixed release |
|---|---|---|
| FortiMail 8.0 | 8.0.0 – 8.0.1 | 8.0.2 or above |
| FortiMail 7.6 | 7.6.0 – 7.6.6 | 7.6.7 or above |
| FortiMail 7.4 | 7.4.0 – 7.4.8 | 7.4.9 or above |
| FortiMail 7.2 | 7.2.0 – 7.2.9 | No fix in branch; migrate to 7.4 |
BleepingComputer reported those three releases as still pending at the time of disclosure. Neither Fortinet nor CISA has given a count of compromised appliances, and no threat actor has been named.
A deadline patching cannot meet
With no build to install, the advisory's interim guidance is the whole of what an operator can do before Sunday: disable Identity-Based Encryption, and keep the management interface off the public internet. Both are subtraction rather than repair.
That matters more than it sounds. Identity-Based Encryption is how FortiMail delivers a secure message to a recipient who has no S/MIME or PGP of their own — the recipient collects it from a portal the appliance itself hosts. Switching IBE off closes that delivery path. For a healthcare provider, a law firm or a bank that routes patient results and client documents through it, that is not a configuration tweak; it is a business process stopping on a Friday afternoon. The second instruction, restricting the management interface, is sound practice that much of the exposed population has evidently not followed, or the vulnerability would not be reachable by an unauthenticated attacker in the first place.
So the honest reading of the October 4 date is not "patch by Sunday." It is "stop being reachable by Sunday." A KEV deadline is a measure of how fast a fleet can be changed, and when no fix exists it becomes a measure of how much functionality an organisation is willing to turn off.
The indicators are the more urgent part
Fortinet did not only publish versions. It published indicators of compromise: modified system libraries and binaries, an altered web server configuration, a shared-object preload entry, cron activity and command-and-control addresses. A vendor that lists a preload hook among its indicators is not describing scanning attempts. It is describing persistence that survives a reboot and, depending on where it sits, can survive an upgrade.
That reorders the work. For an organisation running an affected build with the web interface reachable, the first question is not when a patch arrives but whether the appliance is already owned — and whether the eventual upgrade will carry an implant forward into a system everybody then considers clean. Fortinet's advisory is the place to take the indicator list from, and it belongs in a compromise assessment run before the patch, not after it.
A pattern on the edge
This is the second time in 2026 that Fortinet customers have been handed an actively exploited zero-day whose complete fix lagged the disclosure; CyberScoop covered the same shape in April with FortiClient EMS and CVE-2026-35616. The common factor is not Fortinet specifically. It is the category: security appliances that terminate untrusted traffic, run a web management stack, hold credentials, and sit at the boundary precisely because everything passes through them. Bitget's root-cause report, published two days ago, described an intrusion that began in exactly that class of device.
An appliance bought to inspect mail is, structurally, an internet-facing web server with root on a box that touches every message an organisation sends. The industry keeps rediscovering this one CVE at a time.
Sources: Fortinet PSIRT FG-IR-26-175, BleepingComputer, CISA Known Exploited Vulnerabilities catalog, Rapid7 vulnerability database, runZero, CyberScoop on CVE-2026-35616