Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Fortinet Warns Critical FortiMail Zero-Day is Under Active Attack

Fortinet Warns Critical FortiMail Zero-Day is Under Active Attack

By: Jordan Vector — Cybersecurity Expert

Last updated: October 4, 2026

Human Written
Fortinet Warns Critical FortiMail Zero-Day is Under Active Attack
  • Attackers are using a serious new bug in Fortinet’s FortiMail tool.

  • CISA added the flaw to its danger list right away.

  • The agency gave federal agencies until October 4 to fix it.

Hackers have found and used a dangerous new flaw in FortiMail. FortiMail is a Fortinet email security tool used by many companies. The bug lets attackers break in without a username or password. Once inside, they can place harmful files on a victim’s system.

Experts rank this flaw as critical. The United States Cybersecurity and Infrastructure Security Agency, known as CISA, wasted no time. It quickly added the bug to its list of known threats.

Email gateways like FortiMail sit at a sensitive spot in a company’s network. They filter, scan, and store sensitive mail traffic every single day. A break-in at this level can expose far more than just email.

The flaw now carries the name CVE-2026-104286. It holds a danger score of 9.8 out of 10. That score places it among the most severe bugs tracked this year, according to BleepingComputer.

A Gap in FortiMail’s Front Door

Fortinet shared details about the flaw in a security notice. The notice, called FG-IR-26-175, went live on October 1. The company explained that the bug mixes two separate weak spots. One weak spot lets attackers move through system folders they should not reach. The other involves a coding error tied to a blank character. Experts call this a NULL byte problem.

Together, these two weak spots open a door for hackers. An attacker can send a specially built web request to a FortiMail system. No username or password is needed to pull this off. Once inside, the attacker can plant files inside the management tool. That gives them a foothold to cause more harm later.

Fortinet gave credit to one of its own staff members. Gwendal Guégniaud, from the company’s product security team, found and reported the bug. Fortinet also confirmed that real attackers are already using this flaw.

However, Fortinet has not shared when the attacks first started. It also has not said how many systems got hit. The company has not named who is behind the activity either, as noted in the report by BleepingComputer.

This kind of silence is common early in a breach case. Security teams often need more time to trace an attacker’s full footprint. Fortinet may share more facts once its own review finishes.

Many FortiMail Versions Carry the Risk

The flaw touches several FortiMail versions. These include 8.0.0 through 8.0.1, and 7.6.0 through 7.6.6. Versions 7.4.0 through 7.4.8 are affected too, along with 7.2.0 through 7.2.9. Fortinet plans to release fixed versions soon. These are versions 7.4.9, 7.6.7, and 8.0.2. Anyone still using the older 7.2 line should move up right away. Fortinet suggests upgrading to version 7.4 or newer instead.

Until the new versions arrive, Fortinet shared a short-term fix. Admins can turn off a feature called Identity-Based Encryption. People in the industry often call this feature IBE for short. Turning it off requires using the FortiMail command line tool. Blocking outside access to the management interface also helps a lot. Companies can limit entry to trusted private networks only. This step cuts off the exact path that attackers use.

Fortinet also released a list of clues tied to a possible break-in. These include two suspicious internet addresses, 79.141.169[.]187 and 45.129.0[.]192. The company also named several affected files, among them /data/lib/liblog.so and /data/bin/webconsole.

Other flagged files include /data/bin/mailservice, /data/etc/ld.so.preload, and /bin/smit. The list also names /data/etc/httpd.conf and /data/migadmin.tar.gz. Fortinet shared sample log entries too, so admins can check their own systems for trouble.

CISA Pushes Agencies to Move Fast

CISA placed CVE-2026-104286 on its Known Exploited Vulnerabilities list on October 1. People often call this list the KEV catalog for short. The agency pointed to clear proof that hackers are using the bug right now.

Because of that proof, a strict deadline now applies. All federal civilian agencies must fix the flaw by October 4, 2026. They must also run the required security checks by that date.

CISA also urged companies outside the government to pay attention. The agency says KEV-listed bugs deserve top priority. These flaws carry a proven, real-world risk, unlike bugs that just sit untouched.

This case shows the danger tied to network edge tools. Other attacks have also abused exposed network devices, including a campaign where hackers used Evooo1Bot to turn vulnerable routers into secret proxy servers. Security gateways and mail systems sit right at a network’s edge. That position makes them a prime target for hackers. These tools often guard a path straight into company data.

Attackers know that one working flaw can unlock many targets at once. A single unpatched FortiMail system can become an entry point. From there, hackers may move deeper into a company’s wider network.

Companies running any affected FortiMail version should act now. First, check Fortinet’s list of warning signs against your own systems. Next, turn on the short-term fixes that Fortinet recommends. Finally, install the full patch once it becomes available for your version.

Waiting too long leaves a wide-open door for attackers. Many hackers already know this flaw exists and how it works. Given the KEV listing and the tight deadline, FortiMail teams should move fast.

Share this article

You might also like

ShinyHunters Website Goes Offline After FBI Deadline Expires

ShinyHunters Site Goes Dark as FBI Cyber Investigation Intensifies

The hacker group ShinyHunters’ website went offline on September 30, one day after its FBI deadline expired. The group claimed…

October 2, 2026
Russian Hackers Use New RedFlick Attack to Deliver CosmicPulse Backdoor

Russian State Hackers Use New RedFlick Technique to Deploy CosmicPulse Backdoor

Russian state-linked hackers known as Star Blizzard have started using a new attack method called RedFlick to deliver a dangerous…

October 2, 2026
Russian-Speaking Forum Buyer Seeks Unique WordPress Admin Credentials

Dark Web Buyer Seeks WordPress Admin Access to High-Traffic Websites

A forum actor is seeking valid WordPress administrator access, with unique credentials and higher-traffic sites reportedly attracting more interest. The…

October 2, 2026

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.