Published 3 October 2026 · Severity: Critical (CVSS 9.8)
On 1 October 2026, Fortinet disclosed CVE-2026-104286, a critical vulnerability in FortiMail that is already being exploited in the wild. An unauthenticated attacker can send crafted web requests to the Identity-Based Encryption (IBE) component and write arbitrary files to the appliance, which can lead to full compromise of the mail gateway.
Affected versions
-
- FortiMail 8.0.0 – 8.0.1 → upgrade to 8.0.2 or later
-
- FortiMail 7.6.0 – 7.6.6 → upgrade to 7.6.7 or later
-
- FortiMail 7.4.0 – 7.4.8 → upgrade to 7.4.9 or later
-
- FortiMail 7.2.0 – 7.2.9 → migrate to 7.4 or later
What to do now
- Upgrade to a fixed version as soon as it is available for your branch.
- Until you can upgrade, disable IBE and restrict webmail and management access to trusted networks only.
- Check for signs of compromise: connections to 79.141.169.187 or 45.129.0.192, unexpected files such as /data/etc/ld.so.preload, and unknown archive accounts forwarding mail to remote destinations.
What we are doing
For customers whose FortiMail appliances we manage, our team is reviewing exposure, applying mitigations and scheduling upgrades. We will contact you directly if action is needed on your side.
If you run FortiMail yourself and need help, contact us at Support@arissystem.com or our support phones.
References: Fortinet PSIRT advisory FG-IR-26-175; CVE.org record CVE-2026-104286.