MediumII Cyber Warfare & Critical Infrastructure1 October 2026, Thursday
FortiMail flaw exploited before any patch as CISA gives agencies three days
Fortinet announced on 1 October that a 9.8-rated flaw in its FortiMail email security appliances is being actively exploited. CISA added the flaw to its catalogue of exploited vulnerabilities the same day and gave federal agencies until 4 October. Fixed versions had not been released as of 2 October.
According to CISA's alert of 1 October, CVE-2026-104286 is a path traversal flaw. In other words, an attacker can manipulate file paths to write to folders that should be off limits. Fortinet's advisory FG-IR-26-175 says an unauthenticated attacker can write files and execute commands using specially crafted HTTP or HTTPS requests. The flaw sits in the web interface of the identity-based encryption (IBE) module.
According to SecurityOnline, the flaw has a CVSS score of 9.8, and fixes are planned for versions 8.0.2, 7.6.7 and 7.4.9. Shattered.io wrote that these versions were not available for download as of 2 October and that no patch is planned for the 7.2 branch. Sources diverge on the affected version range: one lists 7.6 branch versions up to 7.6.5, the other up to 7.6.6. CISA's binding directive 26-04 leaves agencies a remediation window of only 3 days. With no patch available, the only options are to disable IBE or take the management interface off the internet.
Talay assessment
Bottom line
A 3-day deadline with no patch available forces agencies to curtail service rather than fix the flaw. If IBE is switched off, encrypted email flows are disrupted. Email gateways are the latest link in a wave of attacks on edge devices. The most likely path is that patches arrive within days, but that the first signs of intrusion surface before then.
Likely effects
- Corporate email securityNegativeWeeks
Organisations using FortiMail must disable IBE until a patch arrives, which could disrupt encrypted email traffic within 3 days.
- Cyber insuranceNegative1–6 months
Unpatched, actively exploited 9.8-rated flaws give insurers grounds to tighten edge device exclusions and premium assessments.
- Institutions in TürkiyeNegativeWeeks
Fortinet products are also widely used by public and private institutions in Türkiye. Local organisations will have to apply the same interim measure.
Possibilities, ranked
- 1Patch arrives, intrusion checks continue55%
Fortinet releases versions 8.0.2, 7.6.7 and 7.4.9 within days, and organisations run retrospective intrusion scans.
Watch: Fixed versions added to Fortinet's advisory FG-IR-26-175
- 2Mass exploitation30%
The flaw is exploited at scale through automated scanning before a patch appears, and the first organisational breaches are announced.
Watch: Security firms' scanning and breach reports targeting FortiMail
- 3Limited impact15%
Exploitation stays targeted, disabling IBE narrows the attack surface and no new cases emerge.
Watch: No new exploitation notice from CISA or Fortinet after 4 October
Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.
Market reaction
Indicators affected
- CVSS score▼ 9.8
- CISA remediation window▼ 3 days
- Released patch▼ None