LiMP VPN
← All news

FortiMail Critical Zero-Day CVE-2026-104286 Under Attack

FortiMail Critical Zero-Day CVE-2026-104286 Under Attack

In short: on October 1, 2026, Fortinet disclosed a critical zero-day vulnerability, CVE-2026-104286 (CVSS 9.8 out of 10), in its FortiMail email security gateway. It combines a path traversal flaw with improper handling of NULL byte characters: a specially crafted HTTP or HTTPS request lets an unauthenticated attacker write a file to an arbitrary location on the appliance's filesystem and execute code. Attackers started exploiting it before Fortinet shipped a patch — CISA added it to its Known Exploited Vulnerabilities catalog and gave US federal agencies until October 4 to remediate. Affected versions: FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1.

What happened

FortiMail is a corporate email security gateway from Fortinet that filters spam and malicious attachments at the network perimeter — and, by design, is usually reachable from the open internet to accept incoming mail. That's exactly what made this flaw critical: a path traversal bug in the admin web interface, combined with improper NULL byte neutralization, lets an attacker with zero credentials write an arbitrary file to disk — enough for remote code execution.

Fortinet confirmed that attacks exploiting the flaw were already underway before public disclosure and a patch existed — a classic zero-day scenario where updating simply isn't an option until a fix ships.

Why this isn't just an enterprise problem

FortiMail looks like a tool for IT departments, not everyday users. But the situation illustrates two things that matter to everyone: first, perimeter devices like email gateways, VPN gateways, and firewalls are exactly how attackers get initial access into corporate networks — and that access eventually turns into breaches of customer personal data, meaning regular people's data. Second, it's another example of a broader rule: anything exposed directly to the internet without an extra layer of protection is a potential target, sometimes before the vendor even knows there's a problem.

We covered a similar pattern — network hardware exploited before a fix exists — in our piece on how a VPN works and why direct internet exposure raises risk.

What Fortinet did

Patches shipped for versions 7.4.9, 7.6.7, and 8.0.2; users on the 7.2.x branch are advised to migrate to 7.4 or later, since no dedicated patch for 7.2.x is planned. CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog and set an October 4, 2026 remediation deadline for US federal agencies, underscoring the severity.

How to protect yourself if you run FortiMail

  • Update FortiMail to 7.4.9, 7.6.7, 8.0.2, or later depending on your branch immediately.
  • If you're on the 7.2.x branch, migrate to 7.4 or higher — there's no patch for 7.2.x.
  • Until patched, restrict access to the FortiMail admin web interface to trusted networks only, not the open internet.
  • Check logs for signs of compromise predating public disclosure — exploitation began before the patch existed.

What this means for everyday users

This flaw has no direct bearing on personal devices — it's about corporate infrastructure. But the underlying principle holds for anyone: services and devices shouldn't be reachable from the internet without a real need, and remote access should go through an encrypted channel instead of directly. For personal traffic on untrusted networks (cafés, hotels, public Wi-Fi), that's the role a VPN plays: the LiMP VPN app encrypts your connection and hides which services you use from the network owner. A verified no-logs policy, plans from 69 ₽/month: LiMP VPN pricing.

Sources