← All security news

FortiMail Zero-Day Flaw Has No Patch Yet

An email gateway appliance icon under attack through an unlocked path-traversal route, with a warning label reading no patch available yet, representing an actively exploited zero-day in Fortinet FortiMail with no fix released

Fortinet has confirmed that attackers are actively exploiting a zero-day flaw in FortiMail, the email security gateway many businesses use to filter and scan mail before it reaches staff inboxes — and, unusually, there is still no patch to install.

Tracked as CVE-2026-104286 and rated 9.8 out of 10, the bug lets an attacker send a crafted web request to the FortiMail management interface without logging in and write arbitrary files onto the underlying system, a combination of a path-traversal flaw and a way to sneak a null byte past the filename check. Fortinet's own product security team found it after noticing it was already being used against real targets. It affects a wide range of currently supported FortiMail releases: 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet lists fixed versions for several of those branches as "upcoming" rather than available today, so the only protection right now is the workaround it published: disabling the IBE (identity-based encryption) feature on the appliance. The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog the same day it was disclosed and gave federal agencies until 4 October 2026 to act — a short deadline that signals how urgently it's being treated.

What this means for your business

If your organisation or your IT provider runs FortiMail — on-premises or virtual appliance — check the version against Fortinet's advisory this week and apply the IBE workaround immediately if you're on an affected release; don't wait for the "upcoming" fix to land before taking action, since the flaw is already being used in attacks. Because the bug lets an attacker write files to the system without ever authenticating, treat any FortiMail box you can't confirm is patched or mitigated as potentially exposed, and have someone check its logs and configuration for anything unexpected rather than assuming "it's just been running fine." If you don't manage your own mail security, ask your provider directly whether they run FortiMail, whether the workaround is already in place, and when they expect the vendor fix to ship — a mail gateway is exactly the kind of appliance that quietly keeps running for months without anyone logging in to check on it.

Questions about your own setup? contact@techleetsolutions.com
Sources: BleepingComputer, The Hacker News, Help Net Security