In brief: Fortinet reports active exploitation of CVE-2026-104286 in FortiMail. The critical flaw allows unauthenticated arbitrary file writes that can lead to code or command execution. As fixed releases remain upcoming, containment and compromise assessment are separate tasks.
File writes before authentication
The vulnerability affects FortiMail's web interface. Insufficient path restriction and null-character handling allow crafted HTTP or HTTPS requests to place files outside the intended directory. Fortinet rates it CVSS 9.8; CISA added it to the Known Exploited Vulnerabilities catalogue on October 1.
Affected versions are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9. Fortinet names 8.0.2, 7.6.7 and 7.4.9 as upcoming targets, while 7.2 users should move to a fixed release on branch 7.4 or later. Those target numbers do not establish that the builds are already generally available.
A workaround is not remediation
Until fixed builds arrive, Fortinet offers three paths: disable Identity-Based Encryption, remove internet access to webmail or restrict it to a trusted private network, or apply the vendor's filter on a fronting web application firewall. The suitable option depends on the deployment's encryption and webmail requirements.
Fortinet also publishes indicators from observed attacks. Closing exposure now cannot prove that the appliance was clean beforehand. Administrators should preserve logs and configuration history, check the current vendor indicators and, where evidence matches, investigate persistence, connected systems and potentially exposed credentials.
Pandorex Analysis
CISA's October 4 deadline applies to affected US federal agencies; it is not a worldwide legal patch deadline. It remains a strong technical priority signal because a mail gateway sits at the network edge and processes untrusted input while fixed builds are pending. The practical sequence is to reduce exposure immediately, preserve evidence, assess compromise and then install the supported fix when available. A configuration change closes the entry point but does not answer whether files or persistence were already left behind.
