News / Cybersecurity
Fortinet Reveals Critical Flaw CVE-2026-104286 Actively Exploited in FortiMail: How to Respond Published on 2 October 2026 by Lawing Tech Newsroom (3 min read)
Fortinet has identified a critical zero-day vulnerability (CVE-2026-104286) in FortiMail, already exploited by attackers to execute arbitrary code without authentication. The flaw, rated CVSS 9.8, affects multiple software versions and requires immediate action.
Video: Setting Up FortiMail | Fortinet Product Demo (Fortinet, YouTube)
What is the flaw, and which versions are affected?
Fortinet has disclosed a critical zero-day vulnerability, referenced as CVE-2026-104286 , affecting its FortiMail product. This vulnerability, scored CVSS 9.8, allows unauthenticated attackers to execute arbitrary code via malicious HTTP/HTTPS requests. It exploits two security flaws: a path traversal (CWE-22) and improper neutralization of NULL characters (CWE-158), according to descriptions provided by OpenCVE .
No patch was available at the time of the alert publication on October 1, 2026, and the expected fixes are versions 7.4.9, 7.6.7, and 8.0.2.
A critical zero-day flaw in FortiMail allows unauthenticated attackers to execute arbitrary code via malicious HTTP/HTTPS requests, jeopardizing email and sensitive data security.
Illustrative photo: network cables (No machine-readable author provided. David.Monniaux assumed (based on copyright claims)., CC BY-SA 3.0)
How do attackers exploit this flaw in practice?
Attackers exploit this flaw by sending specially crafted HTTP/HTTPS requests containing NULL characters, tricking FortiMail into writing files outside authorized directories, as explained by watchTowr . This opens the door to remote code execution, with a risk of full takeover of the mail server.
Indicators of compromise (IOCs) include specific IP addresses (79.141.169.187 and 45.129.0.192) and modified or added files with precise SHA-256 hashes, according to BleepingComputer . Logs from compromised appliances show archived data transfers to remote servers.
What are the recommended workarounds while waiting for patches?
Fortinet has released urgent workarounds to limit risks before patches are released. Among the recommended measures: disable the Identity-Based Encryption (IBE) feature or restrict access to the FortiMail management interface, as specified in advisory FG-IR-26-175 cited by watchTowr . These measures aim to prevent attackers from exploiting the vulnerability via the web interface.
The CERT-FR (via BleepingComputer) highlights that deployments exposing the FortiMail management interface to the Internet are directly accessible by remote attackers. Thus, blocking internet access to this interface is a priority measure.
What this means here: impacts for businesses and administrations in West Africa
For businesses and administrations in Benin and West Africa using FortiMail as an email security solution, this vulnerability poses a major risk. If FortiMail instances are exposed to the Internet or if IBE is enabled, attackers could compromise email servers, leading to leaks of sensitive data or service disruptions. Organizations relying on FortiMail to filter malicious emails or protect against data loss should immediately apply the workarounds recommended by Fortinet.
Public administrations, often prime targets for cyberattacks, could see their email infrastructure at risk. The CISA (via CVETodo) notes that this vulnerability is listed in its catalog of exploited vulnerabilities, with a correction deadline set for October 4, 2026, for federal agencies. Local organizations should follow this recommendation to avoid similar consequences.
Finally, IT service providers (PSI) and consulting firms, such as those in Cotonou, should alert their clients using FortiMail and offer a risk assessment. Updating firewalls or restricting network access could limit exposure until official patches are released.
What are the next steps for affected organizations?
Organizations using FortiMail must first check if their instances are exposed to the Internet or if IBE is enabled. They should then apply the workarounds recommended by Fortinet, as outlined in advisory FG-IR-26-175 . Increased monitoring of logs and network activities is also advised to detect any exploitation attempts.
In the long term, the expected patches (versions 7.4.9, 7.6.7, and 8.0.2) must be applied as soon as they are available. Organizations may also consider migrating to newer versions or alternatives if risks persist. The CISA (via OpenCVE) emphasizes the importance of complying with BOD 26-04 directives for cloud services or discontinuing product use if mitigations are not applicable.
Sources Prepared by Lawing Tech's technology watch from the sources cited. Our editorial charter