A Zero-Click Flaw in FortiMail Is Already Being Exploited — and the Patch Isn't Ready
Published on 10/04/2026 at 23:31 | Editorial boerse-global.de
Security teams running Fortinet's email gateway have a narrow window to act. A maximum-severity vulnerability in FortiMail is under active exploitation, and for several supported branches no fixed release exists yet.
Fortinet disclosed the flaw in advisory FG-IR-26-175 on 1 October 2026. Tracked as CVE-2026-104286, it carries a CVSS score of 9.8 — the top of the scale — and attackers were already using it in the wild, as mytech-home.de reported on 3 October 2026.
What makes it dangerous
Two coding faults combine inside FortiMail's web interface: a path traversal issue (CWE-22) and a null-byte handling error (CWE-158). Both sit in the identity-based encryption (IBE) function, which organisations use to encrypt mail for specific recipients.
No login is required. A single crafted HTTP or HTTPS request lets an outsider write arbitrary files to the system and run malicious code. That combination — unauthenticated, remote, and capable of code execution — explains the urgency.
The US Cybersecurity and Infrastructure Security Agency added the bug to its Known Exploited Vulnerabilities (KEV) catalogue on 1 October 2026, the same day Fortinet published its advisory. Federal agencies in the United States must apply countermeasures and carry out a forensic review by 4 October 2026.
Which versions are exposed
Several release trains are affected. FortiMail 8.0.0 through 8.0.1 awaits version 8.0.2; the 7.6.0–7.6.6 range is waiting on 7.6.7; and 7.4.0 through 7.4.8 will be addressed by 7.4.9.
For 7.2.0 to 7.2.9, Fortinet is not issuing a direct patch at all. Administrators on that branch are advised to migrate to 7.4 or later. The official CVE record also lists versions 7.0.0 through 7.0.9 — a detail picked up by Belgium's cybersecurity authority, the CCB. No virtual patch is available.
Interim defences and signs of compromise
Until the updates land, Fortinet points to workarounds rather than fixes. Organisations can switch off the IBE function entirely, or cut the webmail interface off from the public internet. A web application firewall placed in front of the service can also be configured to block POST requests to the /ibe path that contain ../ sequences.
Indicators of compromise have been published to help spot a successful intrusion. They include connections to the IP addresses 79.141.169[.]187 and 45.129.0[.]192, suspicious cron jobs running with root privileges, and the log entry "User admin logged out from (null)."
Other red flags: an archive account named "archive234", or tampering with system files such as /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice and /data/etc/ld.so.preload.
Part of a wider cluster
FortiMail is not an isolated case. As flowki-club.de reported on 3 October 2026, four critical vulnerabilities in widely deployed enterprise software came to light within just a few days.
Alongside FortiMail, the group includes Dell Container Storage Modules (CSM), where the risks are unauthenticated administrator access and root access to Kubernetes nodes; Fortra's Bastion and access management product BoKS; and version 9.9 of the GitLab AI Gateway.
Guidance circulating in the industry sets different clocks for each. FortiMail patch status should be verified within 48 hours. For Dell CSM and Fortra BoKS, the update window should not stretch beyond a week, while GitLab AI Gateway should be updated at the next maintenance window. Reviewing access and event logs for anomalies is described as urgent in all cases.
